Adobe Acrobat Reader DC Classic Track Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates −2 ✎ 24
Comparison against the immediately-prior release (V1R4). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Removed rules 2
- V-65799 Medium Adobe Reader DC must disable the ability to elevate IE Trusts to Privileged Locations.
- V-65805 Medium Adobe Reader DC must disable the ability to elevate (trusts) certified documents as a Privileged Location.
Content changes 24
- V-65729 Medium checkfix Adobe Reader DC must enable Enhanced Security in a Standalone Application.
- V-65735 Medium checkfix Adobe Reader DC must enable Enhanced Security in a Browser.
- V-65737 Medium checkfix Adobe Reader DC must enable Protected Mode.
- V-65739 Medium checkfix Adobe Reader DC must enable Protected View.
- V-65767 Medium checkfix Adobe Reader DC must Block Websites.
- V-65769 Medium checkfix Adobe Reader DC must block access to Unknown Websites.
- V-65771 Medium checkfix Adobe Reader DC must prevent opening files other than PDF or FDF.
- V-65775 Medium checkfix Adobe Reader DC must block Flash Content.
- V-65777 Low checkfix Adobe Reader DC must disable the ability to change the Default Handler.
- V-65781 Medium checkfix Adobe Reader DC must disable all service access to Document Cloud Services.
- V-65783 Medium checkfix Adobe Reader DC must disable Cloud Synchronization.
- V-65785 Low checkfix Adobe Reader DC must disable the Adobe Repair Installation.
- V-65787 Medium checkfix Adobe Reader DC must disable 3rd Party Web Connectors.
- V-65789 Low checkfix Adobe Reader DC must disable Adobe Send for Signature.
- V-65791 Medium checkfix Adobe Reader DC must disable access to Webmail.
- V-65793 Medium checkfix Adobe Reader DC must disable Online SharePoint Access.
- V-65795 Low checkfix Adobe Reader DC must disable the Adobe Welcome Screen.
- V-65797 Low checkfix Adobe Reader DC must disable Service Upgrades.
- V-65801 Medium checkfix Adobe Reader DC must disable the ability to add Trusted Files and Folders.
- V-65803 Medium checkfix Adobe Reader DC must disable the ability to specify Host-Based Privileged Locations.
- V-65807 Low checkfix Adobe Reader DC must disable periodical uploading of European certificates.
- V-65809 Low checkfix Adobe Reader DC must disable periodical uploading of Adobe certificates.
- V-65813 Medium checkfix Adobe Reader DC must enable FIPS mode.
- V-65815 Low checkfix Adobe Reader DC must disable Acrobat Upsell.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000005
- Vuln IDs
-
- V-65729
- Rule IDs
-
- SV-80219r1_rule
Checks: C-66385r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnhancedSecurityStandalone Type: REG_DWORD Value: 1 If the value for bEnhancedSecurityStandalone is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71773r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnhancedSecurityStandalone Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000010
- Vuln IDs
-
- V-65735
- Rule IDs
-
- SV-80225r1_rule
Checks: C-66393r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnhancedSecurityInBrowser Type: REG_DWORD Value: 1 If the value for bEnhancedSecurityInBrowser is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71781r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnhancedSecurityInBrowser Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000015
- Vuln IDs
-
- V-65737
- Rule IDs
-
- SV-80227r1_rule
Checks: C-66397r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bProtectedMode Type: REG_DWORD Value: 1 If the value for bProtectedMode is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71785r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bProtectedMode Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000020
- Vuln IDs
-
- V-65739
- Rule IDs
-
- SV-80229r1_rule
Checks: C-66401r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: iProtectedView Type: REG_DWORD Value: 2 If the value for iProtectedView is not set to “2” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71789r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: iProtectedView Type: REG_DWORD Value: 2
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000025
- Vuln IDs
-
- V-65767
- Rule IDs
-
- SV-80257r2_rule
Checks: C-66449r4_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iURLPerms Type: REG_DWORD Value: 1 Value: 0 – only with a documented ISSO risk acceptance If the value for iURLPerms is set to “0” and a documented ISSO risk acceptance approving access to the websites is provided, this is not a finding. If the value for “iURLPerms” is not set to “1” and “Type” configured to “REG_DWORD” or does not exist, this is a finding.
Fix: F-71837r2_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iURLPerms Type: REG_DWORD Value: 1 If configuring the system to allow access to websites, obtain documented ISSO approvals and risk acceptance and set “iURLPerms” to “0”.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000030
- Vuln IDs
-
- V-65769
- Rule IDs
-
- SV-80259r1_rule
Checks: C-66451r2_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iUnknownURLPerms Type: REG_DWORD Value: 3 If the value for iUnknownURLPerms is not set to “3” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71839r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iUnknownURLPerms Type: REG_DWORD Value: 3
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000035
- Vuln IDs
-
- V-65771
- Rule IDs
-
- SV-80261r1_rule
Checks: C-66453r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: iFileAttachmentPerms Type: REG_DWORD Value: 1 If the value for iFileAttachmentPerms is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71841r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: iFileAttachmentPerms Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CL-000045
- Vuln IDs
-
- V-65775
- Rule IDs
-
- SV-80265r1_rule
Checks: C-66457r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnableFlash Type: REG_DWORD Value: 0 If the value for bEnableFlash is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71845r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bEnableFlash Type: REG_DWORD Value: 0
- RMF Control
- CM-5
- Severity
- L
- CCI
- CCI-001499
- Version
- ARDC-CL-000050
- Vuln IDs
-
- V-65777
- Rule IDs
-
- SV-80267r1_rule
Checks: C-66459r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bDisablePDFHandlerSwitching Type: REG_DWORD Value: 1 If the value for bDisablePDFHandlerSwitching is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71847r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bDisablePDFHandlerSwitching Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000055
- Vuln IDs
-
- V-65779
- Rule IDs
-
- SV-80269r2_rule
Checks: C-66461r3_chk
Verify the following registry configuration: Note: The Key Name "cCloud" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cCloud Value Name: bAdobeSendPluginToggle Type: REG_DWORD Value: 1 If the value for bAdobeSendPluginToggle is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding. Admin Template path: Computer Configuration > Administrative Templates > Adobe Reader DC Classic > Preferences > 'Send and Track plugin' must be set to 'Disabled'. This policy setting requires the installation of the AcrobatDCClassic custom templates included with the STIG package. "AcrobatDCClassic.admx" and "AcrobatDCClassic.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
Fix: F-71849r3_fix
Configure the following registry value: Note: The Key Name "cCloud" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cCloud Value Name: bAdobeSendPluginToggle Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Reader DC Classic > Preferences > 'Send and Track plugin' to 'Disabled'. This policy setting requires the installation of the AcrobatDCClassic custom templates included with the STIG package. "AcrobatDCClassic.admx" and "AcrobatDCClassic.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000060
- Vuln IDs
-
- V-65781
- Rule IDs
-
- SV-80271r1_rule
Checks: C-66463r1_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bToggleAdobeDocumentServices Type: REG_DWORD Value: 1 If the value for bToggleAdobeDocumentServices is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71851r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bToggleAdobeDocumentServices Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000065
- Vuln IDs
-
- V-65783
- Rule IDs
-
- SV-80273r1_rule
Checks: C-66465r1_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bTogglePrefsSync Type: REG_DWORD Value: 1 If the value for bTogglePrefSync is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71853r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bTogglePrefsSync Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000070
- Vuln IDs
-
- V-65785
- Rule IDs
-
- SV-80275r1_rule
Checks: C-66467r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: For 32 bit: HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\2015\Installer For 64 bit: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe\Acrobat Reader\2015\Installer Value Name: DisableMaintenance Type: REG_DWORD Value: 1 If the value for DisableMaintenance is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71855r1_fix
Configure the following registry value: For 32 bit: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Adobe\Acrobat Reader\2015\Installer For 64 bit: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Wow6432Node\Adobe\Acrobat Reader\2015\Installer Value Name: DisableMaintenance Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000075
- Vuln IDs
-
- V-65787
- Rule IDs
-
- SV-80277r1_rule
Checks: C-66469r1_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bToggleWebConnectors Type: REG_DWORD Value: 1 If the value for bToggleWebConnectors is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71857r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bToggleWebConnectors Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000085
- Vuln IDs
-
- V-65789
- Rule IDs
-
- SV-80279r1_rule
Checks: C-66471r1_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bToggleAdobeSign Type: REG_DWORD Value: 1 If the value for bToggleAdobeSign is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71859r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bToggleAdobeSign Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000090
- Vuln IDs
-
- V-65791
- Rule IDs
-
- SV-80281r1_rule
Checks: C-66473r1_chk
Verify the following registry configuration: Note: The Key Name "cWebmailProfiles" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cWebmailProfiles Value Name: bDisableWebmail Type: REG_DWORD Value: 1 If the value for bDisableWebmail is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71861r1_fix
Configure the following registry value: Note: The Key Name "cWebmailProfiles" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cWebmailProfiles Value Name: bDisableWebmail Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CL-000100
- Vuln IDs
-
- V-65793
- Rule IDs
-
- SV-80283r1_rule
Checks: C-66475r1_chk
Verify the following registry configuration: If configured to an approved DoD SharePoint Server, this is NA. Note: The Key Name "cSharePoint" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cSharePoint Value Name: bDisableSharePointFeatures Type: REG_DWORD Value: 1 If the value for bDisableSharePointFeatures is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71863r1_fix
Configure the following registry value: Note: The Key Name "cSharePoint" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cSharePoint Value Name: bDisableSharePointFeatures Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000115
- Vuln IDs
-
- V-65795
- Rule IDs
-
- SV-80285r1_rule
Checks: C-66477r1_chk
Verify the following registry configuration: Note: The Key Name "cWelcomeScreen" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cWelcomeScreen Value Name: bShowWelcomeScreen Type: REG_DWORD Value: 0 If the value for bShowWelcomeScreen is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71865r1_fix
Configure the following registry value: Note: The Key Name "cWelcomeScreen" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cWelcomeScreen Value Name: bShowWelcomeScreen Type: REG_DWORD Value: 0
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000120
- Vuln IDs
-
- V-65797
- Rule IDs
-
- SV-80287r1_rule
Checks: C-66479r1_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bUpdater Type: REG_DWORD Value: 0 If the value for bUpdater is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71867r1_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown\cServices Value Name: bUpdater Type: REG_DWORD Value: 0
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- ARDC-CL-000315
- Vuln IDs
-
- V-65801
- Rule IDs
-
- SV-80291r1_rule
Checks: C-66483r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bDisableTrustedFolders Type: REG_DWORD Value: 1 If the value for bDisableTrustedFolders is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71871r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bDisableTrustedFolders Type: REG_DWORD Value: 1
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- ARDC-CL-000320
- Vuln IDs
-
- V-65803
- Rule IDs
-
- SV-80293r2_rule
Checks: C-66485r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bDisableTrustedSites Type: REG_DWORD Value: 1 If the value for bDisableTrustedSites is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71873r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bDisableTrustedSites Type: REG_DWORD Value: 1
- RMF Control
- SC-23
- Severity
- L
- CCI
- CCI-002470
- Version
- ARDC-CL-000330
- Vuln IDs
-
- V-65807
- Rule IDs
-
- SV-80297r1_rule
Checks: C-66489r1_chk
Verify the following registry configuration: Note: The Key Names "cDigSig" and "cEUTLDownload" are not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\2015\Security\cDigSig\cEUTLDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0 If the value for bLoadSettingsFromURL is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71877r1_fix
Configure the following registry value: Note: The Key Names "cDigSig" and "cEUTLDownload" are not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_CURRENT_USER Registry Path: \Software\Adobe\Acrobat Reader\2015\Security\cDigSig\cEUTLDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0
- RMF Control
- SC-23
- Severity
- L
- CCI
- CCI-002470
- Version
- ARDC-CL-000335
- Vuln IDs
-
- V-65809
- Rule IDs
-
- SV-80299r1_rule
Checks: C-66491r1_chk
Verify the following registry configuration: Note: The Key Names "cDigSig" and "cAdobeDownload" are not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\2015\Security\cDigSig\cAdobeDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0 If the value for bLoadSettingsFromURL is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71879r1_fix
Configure the following registry value: Note: The Key Names "cDigSig" and "cAdobeDownload" are not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_CURRENT_USER Registry Path: \Software\Adobe\Acrobat Reader\2015\Security\cDigSig\cAdobeDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0
- RMF Control
- SI-2
- Severity
- H
- CCI
- CCI-002605
- Version
- ARDC-CL-000340
- Vuln IDs
-
- V-65811
- Rule IDs
-
- SV-80301r1_rule
Checks: C-66493r1_chk
Determine the method for doing this (e.g., connection to a WSUS server, local procedure, auto update, etc.). Open Adobe Acrobat Reader DC. Navigate to and click on Help >> About Adobe Acrobat Reader DC. Verify that the latest security-related software updates by Adobe are being applied. If the latest security-related software updates by Adobe are not being applied, this is a finding.
Fix: F-71881r1_fix
Apply the latest security-related software updates to the Adobe Acrobat Reader application.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- ARDC-CL-000345
- Vuln IDs
-
- V-65813
- Rule IDs
-
- SV-80303r1_rule
Checks: C-66495r1_chk
Verify the following registry configuration: Note: The Key Names "bFIPSMode" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\2015\AVGeneral Value Name: bFIPSMode Type: REG_DWORD Value: 1 If the value for bFIPSMode is not set to “1” and Type configured to REG_DWORD does not exist, then this is a finding.
Fix: F-71883r1_fix
Configure the following registry value: Note: The Key Names "bFIPSMode" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_CURRENT_USER Registry Path: \Software\Adobe\Acrobat Reader\2015\AVGeneral Value Name: bFIPSMode Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CL-000080
- Vuln IDs
-
- V-65815
- Rule IDs
-
- SV-80305r1_rule
Checks: C-66497r1_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bAcroSuppressUpsell Type: REG_DWORD Value: 1 If the value for bAcroSuppressUpsell is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-71885r1_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\2015\FeatureLockDown Value Name: bAcroSuppressUpsell Type: REG_DWORD Value: 1