Microsoft PowerPoint 2007
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates ✎ 20
Comparison against the immediately-prior release (V4R13). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Content changes 20
- V-17173 Medium descriptioncheckfix Disable user name and password syntax from being used in URLs
- V-17174 Medium descriptioncheckfix Enable IE Bind to Object functionality for instances of IE launched from PowerPoint.
- V-17175 Medium descriptioncheckfix Evaluate Saved from URL mark when launched from PowerPoint
- V-17183 Medium descriptioncheckfix Block navigation to URL embedded in Office products to protect against attack by malformed URL.
- V-17184 Medium descriptioncheckfix Block pop-ups for links that invoke instances of IE from within PowerPoint.
- V-17187 Medium description Disable Trust Bar Notification for unsigned application add-ins -PowerPoint
- V-17322 Medium description Block opening of pre-release versions of file formats new to PowerPoint 2007 through the Compatibility Pack for the 2007 Office system and PowerPoint 2007 Converter - System
- V-17471 Medium description Disable all Trusted Locations.
- V-17473 Medium description Determine whether to force encrypted macros to be scanned in open XML presentations.
- V-17503 Medium description Disable feature that would block older version of office products from saving files to open XML formats.
- V-17518 Medium description Block opening of "open XML" format files created by pre-release versions of PowerPoint
- V-17519 Medium description Block Opening of "Open XML" file types to prevent them automatically executing code.
- V-17520 Medium description Disable settings for content and add-ins that "Allow trusted locations not on computer" that might bypass more stringent security checks.
- V-17521 Medium description Save files default format as backward compatible, not as XML.
- V-17522 Medium descriptioncheck Disable Trust access for VBA into Excel, Word, and PowerPoint.
- V-17545 Medium description Enable Warning Bar settings for VBA macros contained in PowerPoint Files.
- V-17563 Medium description Block PowerPoint from automatically opening converters to view older PowerPoint presentations.
- V-17752 Medium description Make hidden markup invisible - PowerPoint
- V-17788 Medium description Disable the ability to run programs from a PowerPoint presentation.
- V-17809 Medium description Disable the feature to "unblock automatic download of linked images" in PowerPoint.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO104 - PowerPoint
- Vuln IDs
-
- V-17173
- Rule IDs
-
- SV-18179r3_rule
Checks: C-17852r2_chk
Validate the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Disable user name and password” is set to “Enabled” and ‘powerpnt.exe’ and ‘pptview.exe’ are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-16956r3_fix
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Disable user name and password” to “Enabled” and select the "powerpnt.exe" and "pptview.exe" check boxes.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO111 - PowerPoint
- Vuln IDs
-
- V-17174
- Rule IDs
-
- SV-18186r3_rule
Checks: C-17864r4_chk
Validate the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Bind to Object” is set to “Enabled” and "powerpnt.exe" and "pptview.exe" check boxes are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-16962r3_fix
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Bind to Object” to “Enabled” and select the "powerpnt.exe" and "pptview.exe" check boxes.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO117 - PowerPoint
- Vuln IDs
-
- V-17175
- Rule IDs
-
- SV-18201r3_rule
Checks: C-17884r4_chk
Validate the policy value for Computer Configuration -> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Saved from URL” is set to “Enabled” and "powerpnt.exe" and "pptview.exe" check boxes are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-17048r3_fix
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Saved from URL” to “Enabled” and select the "PowerPnt.exe" and "PPTView.exe" check boxes.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO123 - PowerPoint
- Vuln IDs
-
- V-17183
- Rule IDs
-
- SV-18208r3_rule
Checks: C-17891r4_chk
Validate the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Navigate URL” is set to “Enabled” and "powerpnt.exe" and "pptview.exe" check boxes are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding. Fix Text: Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Navigate URL” to “Enabled” and select the "powerpnt.exe" and "pptview.exe" check boxes.
Fix: F-17054r3_fix
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Navigate URL” to “Enabled” and select the "powerpnt.exe" and "pptview.exe" check boxes.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO129 - PowerPoint
- Vuln IDs
-
- V-17184
- Rule IDs
-
- SV-18211r3_rule
Checks: C-17894r4_chk
Validate the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Block popups” is set to “Enabled” and "powerpnt.exe" and "pptview.exe" check boxes are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-17056r3_fix
Set the policy value for Computer Configuration >> Administrative Templates >> Microsoft Office 2007 system (Machine) >> Security Settings >> IE Security “Block popups” to “Enabled” and select the "powerpnt.exe" and "pptview.exe" check boxes.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO131 - PowerPoint
- Vuln IDs
-
- V-17187
- Rule IDs
-
- SV-18222r1_rule
Checks: C-17915r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security Criteria: If the value NoTBPromptUnsignedAddin is REG_DWORD = 1, this is not a finding.
Fix: F-17082r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO210 - Powerpoint
- Vuln IDs
-
- V-17322
- Rule IDs
-
- SV-18562r1_rule
Checks: C-18828r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2007 system -> Office 2007 Converters “Block opening of pre-release versions of file formats new to PowerPoint 2007 through the Compatibility Pack for the 2007 Office system and PowerPoint 2007 Converter” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock Criteria: If the value PowerPoint12BetaFilesFromConverters is REG_DWORD = 1, this is not a finding.
Fix: F-17426r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2007 system -> Office 2007 Converters “Block opening of pre-release versions of file formats new to PowerPoint 2007 through the Compatibility Pack for the 2007 Office system and PowerPoint 2007 Converter” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO133 - Powerpoint
- Vuln IDs
-
- V-17471
- Rule IDs
-
- SV-18530r1_rule
Checks: C-18819r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations “Disable all trusted locations” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\Trusted Locations Criteria: If the value AllLocationsDisabled is REG_DWORD = 1, this is not a finding.
Fix: F-17411r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations “Disable all trusted locations” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO142 - Powerpoint
- Vuln IDs
-
- V-17473
- Rule IDs
-
- SV-18535r1_rule
Checks: C-18822r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Determine whether to force encrypted macros to be scanned in Microsoft PowerPoint Open XML presentations” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security Criteria: If the value PowerPointBypassEncryptedMacroScan is REG_DWORD = 1, this not a finding.
Fix: F-17414r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Determine whether to force encrypted macros to be scanned in Microsoft PowerPoint Open XML presentations” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO155 - PowerPoint
- Vuln IDs
-
- V-17503
- Rule IDs
-
- SV-18575r1_rule
Checks: C-18831r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Save “Block saving of Open Xml file types” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileSaveBlock Criteria: If the value OpenXmlFiles is REG_DWORD = 0, this is not a finding.
Fix: F-17429r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Save “Block saving of Open Xml file types” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO153 - PowerPoint
- Vuln IDs
-
- V-17518
- Rule IDs
-
- SV-18590r1_rule
Checks: C-18834r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Open “Block opening of pre-release versions of file formats new to PowerPoint 2007” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock Criteria: If the value PowerPoint12BetaFiles is REG_DWORD = 1, this is not a finding.
Fix: F-17434r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Open “Block opening of pre-release versions of file formats new to PowerPoint 2007” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO154 - PowerPoint
- Vuln IDs
-
- V-17519
- Rule IDs
-
- SV-18594r1_rule
Checks: C-18837r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Open “Block opening of Open Xml files types” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock Criteria: If the value OpenXmlFiles is REG_DWORD = 0, this is not a finding.
Fix: F-17437r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Open “Block opening of Open Xml files types” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO134 - PowerPoint
- Vuln IDs
-
- V-17520
- Rule IDs
-
- SV-18599r1_rule
Checks: C-18841r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations “Allow Trusted Locations not on the computer” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\Trusted Locations Criteria: If the value AllowNetworkLocations is REG_DWORD = 0, this is not a finding.
Fix: F-17441r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations “Allow Trusted Locations not on the computer” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO139 - PowerPoint
- Vuln IDs
-
- V-17521
- Rule IDs
-
- SV-18607r1_rule
Checks: C-18848r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Save “save files in this format” will be set to “Enabled (PowerPoint 97-2003 Presentation (*.ppt) or Enabled (PowerPoint Presentation (*.pptx)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Options Criteria: If the value DefaultFormat is REG_DWORD = 0 for Powerpoint 97 - 2003 or DefaultFormat is REG_DWORD = 1b (hex) 27 (dec) for Powerpoint 2007 , this is not a finding.
Fix: F-17448r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Save “save files in this format” will be set to “Enabled (PowerPoint 97-2003 Presentation (*.ppt) or Enabled (PowerPoint Presentation (*.pptx)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO146 - PowerPoint
- Vuln IDs
-
- V-17522
- Rule IDs
-
- SV-18611r4_rule
Checks: C-18851r4_chk
Validate the policy value for User Configuration >> Administrative Templates >> Microsoft Office PowerPoint 2007 >> PowerPoint Options >> Security >> Trust Center “Trust access to Visual Basic Project” is set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\ If the value for AccessVBOM is REG_DWORD=0, this is not a finding.
Fix: F-17451r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security -> Trust Center “Trust access to Visual Basic Project” will be set to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO304 - PowerPoint
- Vuln IDs
-
- V-17545
- Rule IDs
-
- SV-18639r1_rule
Checks: C-18856r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security -> Trust Center “VBA Macro Warning Settings” will be set to “Enabled (Trust Bar warning for all macros)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security Criteria: If the value VBAWarnings is REG_DWORD = 2, this is not a finding.
Fix: F-17467r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security -> Trust Center “VBA Macro Warning Settings” will be set to “Enabled (Trust Bar warning for all macros)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO299 - PowerPoint
- Vuln IDs
-
- V-17563
- Rule IDs
-
- SV-18665r1_rule
Checks: C-18864r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Open “Block opening of Converters” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock Criteria: If the value Converters is REG_DWORD = 1, this is not a finding.
Fix: F-17480r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Open “Block opening of Converters” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO290 - PowerPoint
- Vuln IDs
-
- V-17752
- Rule IDs
-
- SV-18943r1_rule
Checks: C-19014r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Make hidden markup visible” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Options Criteria: If the value MarkupOpenSave is REG_DWORD = 1, this is not a finding.
Fix: F-17651r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Make hidden markup visible” will be set to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO289 - PowerPoint
- Vuln IDs
-
- V-17788
- Rule IDs
-
- SV-19007r1_rule
Checks: C-19042r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Run Programs” will be set to “Enabled (disable (don't run any programs))”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security Criteria: If the value RunPrograms is REG_DWORD = 0, this is not a finding
Fix: F-17688r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Run Programs” will be set to “Enabled (disable (don't run any programs))”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO291 - PowerPoint
- Vuln IDs
-
- V-17809
- Rule IDs
-
- SV-19044r1_rule
Checks: C-19070r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Unblock automatic download of linked images” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security Criteria: If the value DownloadImages is REG_DWORD = 0, this is not a finding
Fix: F-17710r1_fix
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Unblock automatic download of linked images” will be set to “Disabled”.