Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +26 −26
Comparison against the immediately-prior release (V1R6). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 26
- V-213168 Medium Adobe Reader DC must enable Enhanced Security in a Standalone Application.
- V-213169 Medium Adobe Reader DC must enable Enhanced Security in a Browser.
- V-213170 Medium Adobe Reader DC must enable Protected Mode.
- V-213171 Medium Adobe Reader DC must enable Protected View.
- V-213172 Medium Adobe Reader DC must Block Websites.
- V-213173 Medium Adobe Reader DC must block access to Unknown Websites.
- V-213174 Medium Adobe Reader DC must prevent opening files other than PDF or FDF.
- V-213175 Medium Adobe Reader DC must block Flash Content.
- V-213176 Low Adobe Reader DC must disable the ability to change the Default Handler.
- V-213177 Low Adobe Reader DC must disable the Adobe Send and Track plugin for Outlook.
- V-213178 Medium Adobe Reader DC must disable all service access to Document Cloud Services.
- V-213179 Medium Adobe Reader DC must disable Cloud Synchronization.
- V-213180 Low Adobe Reader DC must disable the Adobe Repair Installation.
- V-213181 Medium Adobe Reader DC must disable 3rd Party Web Connectors.
- V-213182 Low Adobe Reader DC must disable Acrobat Upsell.
- V-213183 Low Adobe Reader DC must disable Adobe Send for Signature.
- V-213184 Medium Adobe Reader DC must disable access to Webmail.
- V-213185 Medium Adobe Reader DC must disable Online SharePoint Access.
- V-213186 Low Adobe Reader DC must disable the Adobe Welcome Screen.
- V-213187 Low Adobe Reader DC must disable Service Upgrades.
- V-213188 Medium Adobe Reader DC must disable the ability to add Trusted Files and Folders.
- V-213189 Medium Adobe Reader DC must disable the ability to elevate IE Trusts to Privileged Locations.
- V-213190 Low Adobe Reader DC must disable periodical uploading of European certificates.
- V-213191 Low Adobe Reader DC must disable periodical uploading of Adobe certificates.
- V-213192 High Adobe Reader DC must have the latest Security-related Software Updates installed.
- V-213193 Medium Adobe Reader DC must enable FIPS mode.
Removed rules 26
- V-64919 Medium Adobe Reader DC must enable Enhanced Security in a Standalone Application.
- V-64921 Medium Adobe Reader DC must enable Enhanced Security in a Browser.
- V-64923 Medium Adobe Reader DC must enable Protected Mode.
- V-64925 Medium Adobe Reader DC must enable Protected View.
- V-64927 Medium Adobe Reader DC must Block Websites.
- V-64929 Medium Adobe Reader DC must block access to Unknown Websites.
- V-64931 Medium Adobe Reader DC must prevent opening files other than PDF or FDF.
- V-64933 Medium Adobe Reader DC must block Flash Content.
- V-64935 Low Adobe Reader DC must disable the ability to change the Default Handler.
- V-64937 Low Adobe Reader DC must disable the Adobe Send and Track plugin for Outlook.
- V-64939 Medium Adobe Reader DC must disable all service access to Document Cloud Services.
- V-64941 Medium Adobe Reader DC must disable Cloud Synchronization.
- V-64943 Low Adobe Reader DC must disable the Adobe Repair Installation.
- V-64945 Medium Adobe Reader DC must disable 3rd Party Web Connectors.
- V-64947 Low Adobe Reader DC must disable Adobe Send for Signature.
- V-64949 Medium Adobe Reader DC must disable access to Webmail.
- V-64951 Medium Adobe Reader DC must disable Online SharePoint Access.
- V-64953 Low Adobe Reader DC must disable the Adobe Welcome Screen.
- V-64955 Low Adobe Reader DC must disable Service Upgrades.
- V-65667 Medium Adobe Reader DC must disable the ability to add Trusted Files and Folders.
- V-65669 Medium Adobe Reader DC must disable the ability to elevate IE Trusts to Privileged Locations.
- V-65673 Low Adobe Reader DC must disable periodical uploading of European certificates.
- V-65675 Low Adobe Reader DC must disable periodical uploading of Adobe certificates.
- V-65677 High Adobe Reader DC must have the latest Security-related Software Updates installed.
- V-65679 Medium Adobe Reader DC must enable FIPS mode.
- V-66049 Low Adobe Reader DC must disable Acrobat Upsell.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CN-000005
- Vuln IDs
-
- V-213168
- V-64919
- Rule IDs
-
- SV-213168r395811_rule
- SV-79409
Checks: C-14403r276722_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bEnhancedSecurityStandalone Type: REG_DWORD Value: 1 If the value for bEnhancedSecurityStandalone is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14401r276723_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bEnhancedSecurityStandalone Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CN-000010
- Vuln IDs
-
- V-213169
- V-64921
- Rule IDs
-
- SV-213169r395811_rule
- SV-79411
Checks: C-14404r276725_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bEnhancedSecurityInBrowser Type: REG_DWORD Value: 1 If the value for bEnhancedSecurityInBrowser is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14402r276726_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bEnhancedSecurityInBrowser Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CN-000015
- Vuln IDs
-
- V-213170
- V-64923
- Rule IDs
-
- SV-213170r395811_rule
- SV-79413
Checks: C-14405r276728_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bProtectedMode Type: REG_DWORD Value: 1 If the value for bProtectedMode is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14403r276729_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bProtectedMode Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CN-000020
- Vuln IDs
-
- V-213171
- V-64925
- Rule IDs
-
- SV-213171r395811_rule
- SV-79415
Checks: C-14406r276731_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: iProtectedView Type: REG_DWORD Value: 2 If the value for iProtectedView is not set to “2” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14404r276732_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: iProtectedView Type: REG_DWORD Value: 2
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CN-000025
- Vuln IDs
-
- V-213172
- V-64927
- Rule IDs
-
- SV-213172r395811_rule
- SV-79417
Checks: C-14407r276734_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iURLPerms Type: REG_DWORD Value: 1 Value: 0 - only with a documented ISSO risk acceptance If the value for “iURLPerms” is set to “0” and a documented ISSO risk acceptance approving access to websites is provided, this is not a finding. If the value for “iURLPerms” is not set to “1” and “Type” configured to “REG_DWORD” or does not exist, this is a finding.
Fix: F-14405r276735_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iURLPerms Type: REG_DWORD Value: 1 If configuring system to allow access to websites, obtain documented ISSO approvals and risk acceptance and set “iURLPerms” to “0”.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CN-000030
- Vuln IDs
-
- V-213173
- V-64929
- Rule IDs
-
- SV-213173r395811_rule
- SV-79419
Checks: C-14408r276737_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iUnknownURLPerms Type: REG_DWORD Value: 3 If the value for iUnknownURLPerms is not set to “3” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14406r276738_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms Value Name: iUnknownURLPerms Type: REG_DWORD Value: 3
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CN-000035
- Vuln IDs
-
- V-213174
- V-64931
- Rule IDs
-
- SV-213174r395811_rule
- SV-79421
Checks: C-14409r276740_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: iFileAttachmentPerms Type: REG_DWORD Value: 1 If the value for iFileAttachmentPerms is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14407r276741_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: iFileAttachmentPerms Type: REG_DWORD Value: 1
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- ARDC-CN-000045
- Vuln IDs
-
- V-213175
- V-64933
- Rule IDs
-
- SV-213175r395811_rule
- SV-79423
Checks: C-14410r276743_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bEnableFlash Type: REG_DWORD Value: 0 If the value for bEnableFlash is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14408r276744_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bEnableFlash Type: REG_DWORD Value: 0
- RMF Control
- CM-5
- Severity
- L
- CCI
- CCI-001499
- Version
- ARDC-CN-000050
- Vuln IDs
-
- V-213176
- V-64935
- Rule IDs
-
- SV-213176r395850_rule
- SV-79425
Checks: C-14411r276746_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bDisablePDFHandlerSwitching Type: REG_DWORD Value: 1 If the value for bDisablePDFHandlerSwitching is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14409r276747_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bDisablePDFHandlerSwitching Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CN-000055
- Vuln IDs
-
- V-213177
- V-64937
- Rule IDs
-
- SV-213177r766574_rule
- SV-79427
Checks: C-14412r766572_chk
Verify the following registry configuration: Note: The Key Name "cCloud" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cCloud Value Name: bAdobeSendPluginToggle Type: REG_DWORD Value: 1 If the value for bAdobeSendPluginToggle is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding. Admin Template path: Computer Configuration > Administrative Templates > Adobe Reader DC Continuous > Preferences > 'Send and Track plugin' must be set to 'Disabled'.
Fix: F-14410r766573_fix
Configure the following registry value: Note: The Key Name "cCloud" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cCloud Value Name: bAdobeSendPluginToggle Type: REG_DWORD Value: 1 Configure the policy value for Computer Configuration > Administrative Templates > Adobe Reader DC Continuous > Preferences > 'Send and Track plugin' to 'Disabled'.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CN-000060
- Vuln IDs
-
- V-213178
- V-64939
- Rule IDs
-
- SV-213178r395853_rule
- SV-79429
Checks: C-14413r276752_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bToggleAdobeDocumentServices Type: REG_DWORD Value: 1 If the value for bToggleAdobeDocumentServices is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14411r276753_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bToggleAdobeDocumentServices Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CN-000065
- Vuln IDs
-
- V-213179
- V-64941
- Rule IDs
-
- SV-213179r395853_rule
- SV-79431
Checks: C-14414r276755_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bTogglePrefsSync Type: REG_DWORD Value: 1 If the value for bTogglePrefsSync is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14412r276756_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bTogglePrefsSync Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CN-000070
- Vuln IDs
-
- V-213180
- V-64943
- Rule IDs
-
- SV-213180r395853_rule
- SV-79433
Checks: C-14415r276758_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: For 32 bit: HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\DC\Installer For 64 bit: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe\Acrobat Reader\DC\Installer Value Name: DisableMaintenance Type: REG_DWORD Value: 1 If the value for DisableMaintenance is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14413r276759_fix
"Configure the following registry value: For 32 bit: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Adobe\Acrobat Reader\DC\Installer For 64 bit: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Wow6432Node\Adobe\Acrobat Reader\DC\Installer Value Name: DisableMaintenance Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CN-000075
- Vuln IDs
-
- V-213181
- V-64945
- Rule IDs
-
- SV-213181r395853_rule
- SV-79435
Checks: C-14416r276761_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bToggleWebConnectors Type: REG_DWORD Value: 1 If the value for bToggleWebConnectors is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14414r276762_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bToggleWebConnectors Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CN-000080
- Vuln IDs
-
- V-213182
- V-66049
- Rule IDs
-
- SV-213182r395853_rule
- SV-80539
Checks: C-14417r276764_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bAcroSuppressUpsell Type: REG_DWORD Value: 1 If the value for bAcroSuppressUpsell is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14415r276765_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bAcroSuppressUpsell Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CN-000085
- Vuln IDs
-
- V-213183
- V-64947
- Rule IDs
-
- SV-213183r395853_rule
- SV-79437
Checks: C-14418r276767_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bToggleAdobeSign Type: REG_DWORD Value: 1 If the value for bToggleAdobeSign is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14416r276768_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bToggleAdobeSign Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CN-000090
- Vuln IDs
-
- V-213184
- V-64949
- Rule IDs
-
- SV-213184r395853_rule
- SV-79439
Checks: C-14419r276770_chk
Verify the following registry configuration: Note: The Key Name "cWebmailProfiles" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWebmailProfiles Value Name: bDisableWebmail Type: REG_DWORD Value: 1 If the value for bDisableWebmail is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14417r276771_fix
Configure the following registry value: Note: The Key Name "cWebmailProfiles" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWebmailProfiles Value Name: bDisableWebmail Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- ARDC-CN-000100
- Vuln IDs
-
- V-213185
- V-64951
- Rule IDs
-
- SV-213185r395853_rule
- SV-79441
Checks: C-14420r276773_chk
Verify the following registry configuration: If configured to an approved DoD SharePoint Server, this is NA. Note: The Key Name "cSharePoint" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cSharePoint Value Name: bDisableSharePointFeatures Type: REG_DWORD Value: 1 If the value for bDisableSharePointFeatures is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14418r276774_fix
Configure the following registry value: Note: The Key Name "cSharePoint" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cSharePoint Value Name: bDisableSharePointFeatures Type: REG_DWORD Value: 1
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CN-000115
- Vuln IDs
-
- V-213186
- V-64953
- Rule IDs
-
- SV-213186r395853_rule
- SV-79443
Checks: C-14421r276776_chk
Verify the following registry configuration: Note: The Key Name "cWelcomeScreen" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWelcomeScreen Value Name: bShowWelcomeScreen Type: REG_DWORD Value: 0 If the value for bShowWelcomeScreen is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14419r276777_fix
Configure the following registry value: Note: The Key Name "cWelcomeScreen" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWelcomeScreen Value Name: bShowWelcomeScreen Type: REG_DWORD Value: 0
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- ARDC-CN-000120
- Vuln IDs
-
- V-213187
- V-64955
- Rule IDs
-
- SV-213187r395853_rule
- SV-79445
Checks: C-14422r276779_chk
Verify the following registry configuration: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bUpdater Type: REG_DWORD Value: 0 If the value for bUpdater is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14420r276780_fix
Configure the following registry value: Note: The Key Name "cServices" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices Value Name: bUpdater Type: REG_DWORD Value: 0
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- ARDC-CN-000315
- Vuln IDs
-
- V-213188
- V-65667
- Rule IDs
-
- SV-213188r400006_rule
- SV-80157
Checks: C-14423r276782_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bDisableTrustedFolders Type: REG_DWORD Value: 1 If the value for bDisableTrustedFolders is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14421r276783_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bDisableTrustedFolders Type: REG_DWORD Value: 1
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- ARDC-CN-000320
- Vuln IDs
-
- V-213189
- V-65669
- Rule IDs
-
- SV-213189r400006_rule
- SV-80159
Checks: C-14424r276785_chk
Verify the following registry configuration: Utilizing the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bDisableTrustedSites Type: REG_DWORD Value: 1 If the value for bDisableTrustedSites is not set to “1” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14422r276786_fix
Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown Value Name: bDisableTrustedSites Type: REG_DWORD Value: 1
- RMF Control
- SC-23
- Severity
- L
- CCI
- CCI-002470
- Version
- ARDC-CN-000330
- Vuln IDs
-
- V-213190
- V-65673
- Rule IDs
-
- SV-213190r400378_rule
- SV-80163
Checks: C-14425r276788_chk
Verify the following registry configuration: Note: The Key Names "cDigSig" and "cEUTLDownload" are not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Security\cDigSig\cEUTLDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0 If the value for bLoadSettingsFromURL is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14423r276789_fix
Configure the following registry value: Note: The Key Names "cDigSig" and "cEUTLDownload" are not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_CURRENT_USER Registry Path: \Software\Adobe\Acrobat Reader\DC\Security\cDigSig\cEUTLDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0
- RMF Control
- SC-23
- Severity
- L
- CCI
- CCI-002470
- Version
- ARDC-CN-000335
- Vuln IDs
-
- V-213191
- V-65675
- Rule IDs
-
- SV-213191r400378_rule
- SV-80165
Checks: C-14426r276791_chk
Verify the following registry configuration: Note: The Key Names "cDigSig" and "cAdobeDownload" are not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Security\cDigSig\cAdobeDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0 If the value for bLoadSettingsFromURL is not set to “0” and Type configured to REG_DWORD or does not exist, then this is a finding.
Fix: F-14424r276792_fix
Configure the following registry value: Note: The Key Names "cDigSig" and "cAdobeDownload" are not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_CURRENT_USER Registry Path: \Software\Adobe\Acrobat Reader\DC\Security\cDigSig\cAdobeDownload Value Name: bLoadSettingsFromURL Type: REG_DWORD Value: 0
- RMF Control
- SI-2
- Severity
- H
- CCI
- CCI-002605
- Version
- ARDC-CN-000340
- Vuln IDs
-
- V-213192
- V-65677
- Rule IDs
-
- SV-213192r400525_rule
- SV-80167
Checks: C-14427r276794_chk
Determine the method for doing this (e.g., connection to a WSUS server, local procedure, auto update, etc.). Open Adobe Acrobat Reader DC. Navigate to and click on Help >> About Adobe Acrobat Reader DC. Verify that the latest security-related software updates by Adobe are being applied. If the latest security-related software updates by Adobe are not being applied, this is a finding.
Fix: F-14425r276795_fix
Apply the latest security-related software updates to the Adobe Acrobat Reader application.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- ARDC-CN-000345
- Vuln IDs
-
- V-213193
- V-65679
- Rule IDs
-
- SV-213193r400876_rule
- SV-80169
Checks: C-14428r276797_chk
Verify the following registry configuration: Note: The Key Names "bFIPSMode" is not created by default in the Adobe Reader DC install and must be created. Utilizing the Registry Editor, navigate to the following: HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral Value Name: bFIPSMode Type: REG_DWORD Value: 1 If the value for bFIPSMode is not set to “1” and Type configured to REG_DWORD does not exist, then this is a finding.
Fix: F-14426r276798_fix
Configure the following registry value: Note: The Key Names "bFIPSMode" is not created by default in the Adobe Reader DC install and must be created. Registry Hive: HKEY_CURRENT_USER Registry Path: \Software\Adobe\Acrobat Reader\DC\AVGeneral Value Name: bFIPSMode Type: REG_DWORD Value: 1