Microsoft OneNote 2010 Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +12 −11
Comparison against the immediately-prior release (V1R7). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 12
- V-242010 Medium Disabling of user name and password syntax from being used in URLs must be enforced.
- V-242011 Medium Enabling IE Bind to Object functionality must be present.
- V-242012 Medium Saved from URL mark to assure Internet zone processing must be enforced.
- V-242013 Medium Navigation to URL's embedded in Office products must be blocked.
- V-242014 Medium Scripted Window Security must be enforced.
- V-242015 Medium Add-on Management functionality must be allowed.
- V-242016 Medium Data Execution Prevention must be enforced.
- V-242017 Medium Links that invoke instances of IE from within an Office product must be blocked.
- V-242018 Medium File Downloads must be configured for proper restrictions.
- V-242019 Medium Protection from zone elevation must be enforced.
- V-242020 Medium ActiveX Installs must be configured for proper restriction.
- V-270896 High The version of OneNote running on the system must be a supported version.
Removed rules 11
- V-17173 Medium Disabling of user name and password syntax from being used in URLs must be enforced.
- V-17174 Medium Enabling IE Bind to Object functionality must be present.
- V-17175 Medium Saved from URL mark to assure Internet zone processing must be enforced.
- V-17183 Medium Navigation to URL's embedded in Office products must be blocked.
- V-17184 Medium Links that invoke instances of IE from within an Office product must be blocked.
- V-26584 Medium Add-on Management functionality must be allowed.
- V-26585 Medium Protection from zone elevation must be enforced.
- V-26586 Medium ActiveX Installs must be configured for proper restriction.
- V-26587 Medium File Downloads must be configured for proper restrictions.
- V-26588 Medium Scripted Window Security must be enforced.
- V-26590 Medium Data Execution Prevention must be enforced.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO104 - OneNote
- Vuln IDs
-
- V-242010
- V-17173
- Rule IDs
-
- SV-242010r961092_rule
- SV-33896
Checks: C-45285r708384_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Disable user name and password" must be "Enabled" and a check in the "onent.exe" check box must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45244r708358_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Disable user name and password" to "Enabled" and place a check in the "onent.exe" check box.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- DTOO111 - OneNote
- Vuln IDs
-
- V-242011
- V-17174
- Rule IDs
-
- SV-242011r960921_rule
- SV-33891
Checks: C-45286r708360_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Bind to Object" must be "Enabled" and a check in the "onent.exe" check box must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45245r708361_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Bind to Object" to "Enabled" and place a check in the "onent.exe" check box.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO117 - OneNote
- Vuln IDs
-
- V-242012
- V-17175
- Rule IDs
-
- SV-242012r1055876_rule
- SV-33917
Checks: C-45287r1055876_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Saved from URL" must be "Enabled" and a check in the "onent.exe" check box must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45246r708332_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Saved from URL" to "Enabled" and place a check in the "onent.exe" check box.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO123 - OneNote
- Vuln IDs
-
- V-242013
- V-17183
- Rule IDs
-
- SV-242013r961092_rule
- SV-33899
Checks: C-45288r708334_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Navigate URL" must be "Enabled" and a check in the "onent.exe" check box must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45247r708335_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Navigate URL" to "Enabled" and place a check in the "onent.exe" check box.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- DTOO124 - OneNote
- Vuln IDs
-
- V-242014
- V-26588
- Rule IDs
-
- SV-242014r960921_rule
- SV-33920
Checks: C-45289r708376_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Scripted Window Security Restrictions" must be set to "Enabled" and "onent.exe" is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45248r708377_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Scripted Window Security Restrictions" to "Enabled" and "onent.exe" is checked.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTOO126 - OneNote
- Vuln IDs
-
- V-242015
- V-26584
- Rule IDs
-
- SV-242015r961086_rule
- SV-33888
Checks: C-45290r708340_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Add-on Management" must be set to "Enabled" and "onent.exe" is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45249r708365_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Add-on Management" to "Enabled" and "onent.exe" is checked.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO128 - OneNote
- Vuln IDs
-
- V-242016
- V-26590
- Rule IDs
-
- SV-242016r961092_rule
- SV-33934
Checks: C-45291r708379_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft OneNote 2010 -> OneNote Options -> Security -> Trust Center "Turn off Data Execution Prevention" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\onenote\security Criteria: If the value EnableDEP is REG_DWORD = 1, this is not a finding.
Fix: F-45250r708380_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft OneNote 2010 -> OneNote Options -> Security -> Trust Center "Turn off Data Execution Prevention" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTOO129 - OneNote
- Vuln IDs
-
- V-242017
- V-17184
- Rule IDs
-
- SV-242017r961086_rule
- SV-33893
Checks: C-45292r708346_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Block popups" must be "Enabled" and "onent.exe" is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45251r708347_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Block popups" to "Enabled" and select "onent.exe".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001169
- Version
- DTOO132 - OneNote
- Vuln IDs
-
- V-242018
- V-26587
- Rule IDs
-
- SV-242018r961089_rule
- SV-33914
Checks: C-45293r708373_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Restrict File Download" must be set to "Enabled" and "onent.exe" is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45252r708374_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Restrict File Download" to "Enabled" and "onent.exe" is checked.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- DTOO209 - OneNote
- Vuln IDs
-
- V-242019
- V-26585
- Rule IDs
-
- SV-242019r960921_rule
- SV-33902
Checks: C-45294r708367_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Protection From Zone Elevation" must be set to "Enabled" and "onent.exe" is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45253r708368_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Protection From Zone Elevation" to "Enabled" and "onent.exe" is checked.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-002460
- Version
- DTOO211 - OneNote
- Vuln IDs
-
- V-242020
- V-26586
- Rule IDs
-
- SV-242020r961779_rule
- SV-33906
Checks: C-45295r849878_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Restrict ActiveX Install" must be set to "Enabled" and "onent.exe" is checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL Criteria: If the value onenote.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45254r849879_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Restrict ActiveX Install" to "Enabled" and "onent.exe" is checked.
- RMF Control
- SI-2
- Severity
- H
- CCI
- CCI-002605
- Version
- DTOO999 - OneNote
- Vuln IDs
-
- V-270896
- Rule IDs
-
- SV-270896r1055869_rule
Checks: C-74937r1055867_chk
OneNote 2010 is no longer supported by the vendor. If the system is running OneNote 2010, this is a finding.
Fix: F-74838r1055868_fix
Upgrade to a supported version.