Adobe Acrobat Professional DC Continuous Track STIG SCAP Benchmark
Open a previous version of this SCAP benchmark.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- AADC-CN-000205
- Vuln IDs
- V-213117
- Rule IDs
- SV-213117r766511_rule
Fix: F-14352r766510_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown Value Name: bEnhancedSecurityStandalone Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > Security (Enhanced) > 'Enable Enhanced Security Standalone' to 'Enabled'.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- AADC-CN-000210
- Vuln IDs
- V-213118
- Rule IDs
- SV-213118r766514_rule
Fix: F-14353r766513_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown Value Name: bEnhancedSecurityInBrowser Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > Security (Enhanced) > 'Enable Enhanced Security In Browser' to 'Enabled'.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- AADC-CN-000275
- Vuln IDs
- V-213119
- Rule IDs
- SV-213119r766517_rule
Fix: F-14354r766516_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown Value Name: iFileAttachmentPerms Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > Trust Manager > 'Allow opening of non-PDF file attachments with external applications' to 'Disabled'.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- AADC-CN-000280
- Vuln IDs
- V-213120
- Rule IDs
- SV-213120r766520_rule
Fix: F-14355r766519_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cDefaultLaunchURLPerms\ Value Name: iUnknownURLPerms Type: REG_DWORD Value: 3 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > Trust Manager > 'Access to unknown websites' to 'Enabled' and select 'Block access' in the drop down box.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- AADC-CN-000285
- Vuln IDs
- V-213121
- Rule IDs
- SV-213121r766523_rule
Fix: F-14356r766522_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cDefaultLaunchURLPerms\ Value Name: iURLPerms Type: REG_DWORD Value: 1 The setting may be set to "0" if a documented risk acceptance approving the websites is approved by the ISSO/AO. Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > Trust Manager > 'Access to websites' to 'Enabled' and select 'Block PDF files access to all web sites' in the drop down box. Select 'Custom setting' if needed and provide a documented risk acceptance approved by the ISSO/AO approving the websites.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- AADC-CN-000290
- Vuln IDs
- V-213122
- Rule IDs
- SV-213122r766526_rule
Fix: F-14357r766525_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown Value Name: bEnableFlash Type: REG_DWORD Value: 0 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > 'Enable Flash' to 'Disabled'.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- AADC-CN-000295
- Vuln IDs
- V-213123
- Rule IDs
- SV-213123r766529_rule
Fix: F-14358r766528_fix
Configure the following registry value: Note: The Key Name "cCloud" is not created by default in the Acrobat Pro DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cCloud Value Name: bAdobeSendPluginToggle Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > 'Send and Track plugin' to 'Disabled'.
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- AADC-CN-000840
- Vuln IDs
- V-213124
- Rule IDs
- SV-213124r766532_rule
Fix: F-14359r766531_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown Value Name: bDisableTrustedFolders Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > Security (Enhanced) > 'Privileged folder locations' to 'Disabled'.
- RMF Control
- SC-23
- Severity
- L
- CCI
- CCI-002470
- Version
- AADC-CN-000990
- Vuln IDs
- V-213126
- Rule IDs
- SV-213126r766535_rule
Fix: F-14361r766534_fix
Configure the following registry value: Note: The Key Name "cEUTLDownload" is not created by default in the Acrobat Pro DC install and must be created. Registry Hive: HKEY_CURRENT_USER Registry Path: \Software\Adobe\Adobe Acrobat\DC\Security\cDigSig\cEUTLDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0 Configure the policy value for User Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > Trust Manager > 'Load trusted certificates from an Adobe EUTL server' to 'Disabled'.
- RMF Control
- SC-39
- Severity
- M
- CCI
- CCI-002530
- Version
- AADC-CN-001010
- Vuln IDs
- V-213127
- Rule IDs
- SV-213127r766538_rule
Fix: F-14362r766537_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown Value Name: bProtectedMode Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > 'Protected Mode' to 'Enabled'.
- RMF Control
- SC-39
- Severity
- M
- CCI
- CCI-002530
- Version
- AADC-CN-001015
- Vuln IDs
- V-213128
- Rule IDs
- SV-213128r766541_rule
Fix: F-14363r766540_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown Value Name: iProtectedView Type: REG_DWORD Value: 2 Configure the policy value for Computer Configuration > Administrative Template > Adobe Acrobat Pro DC Continuous > Preferences > Security (Enhanced) > 'Protected View' to 'Enabled' and select 'All files' in the drop down box.
- RMF Control
- CM-5
- Severity
- L
- CCI
- CCI-001499
- Version
- AADC-CN-001280
- Vuln IDs
- V-213130
- Rule IDs
- SV-213130r766544_rule
Fix: F-14365r766543_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown Value Name: bDisablePDFHandlerSwitching Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Template > Adobe Acrobat Pro DC Continuous > Preferences > General > 'Disable PDF handler switching' to 'Enabled'.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- AADC-CN-001285
- Vuln IDs
- V-213131
- Rule IDs
- SV-213131r766547_rule
Fix: F-14366r766546_fix
Configure the following registry value: Note: The Key Name "cCloud" is not created by default in the Acrobat Pro DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cCloud Value Name: bDisableADCFileStore Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Template > Adobe Acrobat Pro DC Continuous > Preferences > 'Store files on Adobe.com' to 'Disabled'.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- AADC-CN-001290
- Vuln IDs
- V-213132
- Rule IDs
- SV-213132r766550_rule
Fix: F-14367r766549_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cServices Value Name: bTogglePrefsSync Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Template > Adobe Acrobat Pro DC Continuous > Preferences > 'Cloud Synchronization' to 'Disabled'.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- AADC-CN-001295
- Vuln IDs
- V-213133
- Rule IDs
- SV-213133r766553_rule
Fix: F-14368r766552_fix
Configure the following registry value: For 32 bit: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Adobe\Adobe Acrobat\DC\Installer For 64 bit: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Wow6432Node\Adobe\Adobe Acrobat\DC\Installer Value Name: DisableMaintenance Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Template > Adobe Acrobat Pro DC Continuous > Preferences > Help > 'Repair Installation on 32/64 bit' to 'Disabled'.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- AADC-CN-001300
- Vuln IDs
- V-213134
- Rule IDs
- SV-213134r766556_rule
Fix: F-14369r766555_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cServices Value Name: bToggleWebConnectors Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Template > Adobe Acrobat Pro DC Continuous > Preferences > 'Third-party web connectors' to 'Disabled'.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- AADC-CN-001305
- Vuln IDs
- V-213135
- Rule IDs
- SV-213135r766559_rule
Fix: F-14370r766558_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cWebmailProfiles Value Name: bDisableWebmail Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Template > Adobe Acrobat Pro DC Continuous > Preferences > 'WebMail' to 'Disabled'.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- AADC-CN-001310
- Vuln IDs
- V-213136
- Rule IDs
- SV-213136r766562_rule
Fix: F-14371r766561_fix
Configure the following registry value: Note: The Key Name "cWelcomeScreen" is not created by default in the Acrobat Pro DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cWelcomeScreen Value Name: bShowWelcomeScreen Type: REG_DWORD Value: 0 Configure the policy value for Computer Configuration > Administrative Template > Adobe Acrobat Pro DC Continuous > Preferences > 'Welcome Screen' to 'Disabled'.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- AADC-CN-001315
- Vuln IDs
- V-213137
- Rule IDs
- SV-213137r766565_rule
Fix: F-14372r766564_fix
Configure the following registry value: Note: The Key Name "cSharePoint" is not created by default in the Acrobat Pro DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cSharePoint Value Name: bDisableSharePointFeatures Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Template > Adobe Acrobat Pro DC Continuous > Preferences > 'SharePoint and Office 365 access' to 'Disabled'.
- RMF Control
- SC-23
- Severity
- L
- CCI
- CCI-002470
- Version
- AADC-CN-001320
- Vuln IDs
- V-213138
- Rule IDs
- SV-213138r766568_rule
Fix: F-14373r766567_fix
Configure the following registry value: Registry Hive: HKEY_CURRENT_USER Registry Path: \Software\Adobe\Adobe Acrobat\DC\Security\cDigSig\cAdobeDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0 Configure the policy value for User Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > Trust Manager > 'Load trusted certificates from an Adobe AATL server' to 'Disabled'.
- RMF Control
- CM-5
- Severity
- L
- CCI
- CCI-001813
- Version
- AADC-CN-001325
- Vuln IDs
- V-213139
- Rule IDs
- SV-213139r766571_rule
Fix: F-14374r766570_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown Value Name: bDisableTrustedSites Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > Security (Enhanced) > 'Privileged host locations' to 'Disabled'.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- AADC-CN-000955
- Vuln IDs
- V-245874
- Rule IDs
- SV-245874r766580_rule
Fix: F-49260r766582_fix
Configure the following registry value: Registry Hive: HKEY_CURRENT_USER Registry Path: \Software\Adobe\Adobe Acrobat\DC\AVGeneral Value Name: bFIPSMode Type: REG_DWORD Value: 1 Configure the policy value for User Configuration > Administrative Templates > Adobe Acrobat Pro DC Continuous > Preferences > 'Enable FIPS' to 'Enabled'.