Check: DTOO130
Microsoft Access 2013 STIG:
DTOO130
(in versions v1 r7 through v1 r4)
Title
The configuration for enabling of hyperlinks must be enforced. (Cat II impact)
Discussion
Access underlines hyperlinks that appear in tables, queries, forms, and reports. If this configuration is changed, users might click on dangerous hyperlinks without realizing it, which could pose a security risk.
Check Content
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Access 2013-> Application Settings -> Web Options... -> General "Underline Hyperlinks" is set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\access\internet Criteria: If the value DoNotUnderlineHyperlinks is REG_DWORD = 0, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Access 2013 -> Application Settings -> Web Options... -> General "Underline Hyperlinks" to "Enabled".
Additional Identifiers
Rule ID: SV-242320r961779_rule
Vulnerability ID: V-242320
Group Title: SRG-APP-000488
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002460 |
Enforce organization-defined actions prior to executing mobile code. |
Controls
Number | Title |
---|---|
SC-18(4) |
Prevent Automatic Execution |