Adobe Acrobat Reader DC Classic Track Security Technical Implementation Guide
Open a previous version of this SCAP benchmark.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000005
- Vuln IDs
- V-65729
- Rule IDs
- SV-80219r1_rule
Fix: F-71773r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnhancedSecurityStandalone Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000010
- Vuln IDs
- V-65735
- Rule IDs
- SV-80225r1_rule
Fix: F-71781r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnhancedSecurityInBrowser Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000015
- Vuln IDs
- V-65737
- Rule IDs
- SV-80227r1_rule
Fix: F-71785r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bProtectedMode Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000020
- Vuln IDs
- V-65739
- Rule IDs
- SV-80229r1_rule
Fix: F-71789r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: iProtectedView Type: REG_DWORD Value: 2
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000025
- Vuln IDs
- V-65767
- Rule IDs
- SV-80257r2_rule
Fix: F-71837r2_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iURLPerms Type: REG_DWORD Value: 1 If configuring the system to allow access to websites, obtain documented ISSO approvals and risk acceptance and set “iURLPerms” to “0”.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000030
- Vuln IDs
- V-65769
- Rule IDs
- SV-80259r1_rule
Fix: F-71839r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iUnknownURLPerms Type: REG_DWORD Value: 3
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000035
- Vuln IDs
- V-65771
- Rule IDs
- SV-80261r1_rule
Fix: F-71841r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: iFileAttachmentPerms Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000045
- Vuln IDs
- V-65775
- Rule IDs
- SV-80265r1_rule
Fix: F-71845r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnableFlash Type: REG_DWORD Value: 0
- RMF Control
- CM-5
- Severity
- L
- CCI
- CCI-001499
- Version
- ARDC-CL-000050
- Vuln IDs
- V-65777
- Rule IDs
- SV-80267r1_rule
Fix: F-71847r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bDisablePDFHandlerSwitching Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000055
- Vuln IDs
- V-65779
- Rule IDs
- SV-80269r2_rule
Fix: F-71849r3_fix
Configure the following registry value: Note: The Key Name "cCloud" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cCloud Value Name: bAdobeSendPluginToggle Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Reader DC Classic > Preferences > 'Send and Track plugin' to 'Disabled'. This policy setting requires the installation of the AcrobatDCClassic custom templates included with the STIG package. "AcrobatDCClassic.admx" and "AcrobatDCClassic.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000060
- Vuln IDs
- V-65781
- Rule IDs
- SV-80271r1_rule
Fix: F-71851r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bToggleAdobeDocumentServices Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000065
- Vuln IDs
- V-65783
- Rule IDs
- SV-80273r1_rule
Fix: F-71853r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bTogglePrefsSync Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000070
- Vuln IDs
- V-65785
- Rule IDs
- SV-80275r1_rule
Fix: F-71855r1_fix
Configure the following registry value: For 32 bit: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Adobe\Acrobat Reader\2015\Installer For 64 bit: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Wow6432Node\Adobe\Acrobat Reader\2015\Installer Value Name: DisableMaintenance Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000075
- Vuln IDs
- V-65787
- Rule IDs
- SV-80277r1_rule
Fix: F-71857r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bToggleWebConnectors Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000085
- Vuln IDs
- V-65789
- Rule IDs
- SV-80279r1_rule
Fix: F-71859r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bToggleAdobeSign Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000090
- Vuln IDs
- V-65791
- Rule IDs
- SV-80281r1_rule
Fix: F-71861r1_fix
Configure the following registry value: Note: The Key Name "cWebmailProfiles" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cWebmailProfiles Value Name: bDisableWebmail Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000100
- Vuln IDs
- V-65793
- Rule IDs
- SV-80283r1_rule
Fix: F-71863r1_fix
Configure the following registry value: Note: The Key Name "cSharePoint" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cSharePoint Value Name: bDisableSharePointFeatures Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000115
- Vuln IDs
- V-65795
- Rule IDs
- SV-80285r1_rule
Fix: F-71865r1_fix
Configure the following registry value: Note: The Key Name "cWelcomeScreen" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cWelcomeScreen Value Name: bShowWelcomeScreen Type: REG_DWORD Value: 0
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000120
- Vuln IDs
- V-65797
- Rule IDs
- SV-80287r1_rule
Fix: F-71867r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bUpdater Type: REG_DWORD Value: 0
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- ARDC-CL-000315
- Vuln IDs
- V-65801
- Rule IDs
- SV-80291r1_rule
Fix: F-71871r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bDisableTrustedFolders Type: REG_DWORD Value: 1
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- ARDC-CL-000320
- Vuln IDs
- V-65803
- Rule IDs
- SV-80293r2_rule
Fix: F-71873r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bDisableTrustedSites Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000080
- Vuln IDs
- V-65815
- Rule IDs
- SV-80305r1_rule
Fix: F-71885r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bAcroSuppressUpsell Type: REG_DWORD Value: 1