STIGQter STIGQter: STIG Summary: Microsoft Word 2013 STIG Version: 1 Release: 6 Benchmark Date: 27 Apr 2018:

Macros must be blocked from running in Office 2013 files from the Internet.

DISA Rule

SV-87481r1_rule

Vulnerability Number

V-72829

Group Title

DTOO600 - Macros must be blocked from running in Office 2013 files from the Internet.

Rule Version

DTOO600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set the policy value for User Configuration >> Administrative Templates >> Microsoft Word 2013 >> Word Options >> Security >> Trust Center "Block macros from running in Office files from the Internet" to "Enabled".

Check Contents

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Word 2013 >> Word Options >> Security >> Trust Center "Block macros from running in Office files from the Internet" is set to "Enabled".

Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\15.0\word\security

If the value "blockcontentexecutionfrominternet" is REG_DWORD = 1, this is not a finding.

Vulnerability Number

V-72829

Documentable

False

Rule Version

DTOO600

Severity Override Guidance

Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Word 2013 >> Word Options >> Security >> Trust Center "Block macros from running in Office files from the Internet" is set to "Enabled".

Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\15.0\word\security

If the value "blockcontentexecutionfrominternet" is REG_DWORD = 1, this is not a finding.

Check Content Reference

M

Target Key

2487

Comments