Check: DTOO194 - Office System
Microsoft Office System 2010 STIG:
DTOO194 - Office System
(in versions v1 r12 through v1 r10)
Title
Hyperlink warnings for Office must be configured for use. (Cat II impact)
Discussion
Unsafe hyperlinks are links that might pose a security risk if users click them. Clicking an unsafe link could compromise the security of sensitive information or harm the computer. Links that Office considers unsafe include links to executable files, TIFF files, and Microsoft Document Imaging (MDI) files. Other unsafe links are those using protocols considered to be unsafe, including msn, nntp, mms, outlook, and stssync.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Suppress hyperlink warnings” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DisableHyperLinkWarning is REG_DWORD = 0, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Suppress hyperlink warnings” to “Disabled”.
Additional Identifiers
Rule ID: SV-33469r1_rule
Vulnerability ID: V-17659
Group Title: DTOO194 - Hyperlink warnings for Office
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002460 |
The information system enforces organization-defined actions prior to executing mobile code. |
Controls
Number | Title |
---|---|
SC-18 (4) |
Prevent Automatic Execution |