Microsoft PowerPoint 2010 Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +31 −31
Comparison against the immediately-prior release (V1R7). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 31
- V-242137 Medium Disabling of user name and password syntax from being used in URLs must be enforced.
- V-242138 Medium Blocking as default file block opening behavior must be enforced.
- V-242139 Medium Enabling IE Bind to Object functionality must be present.
- V-242140 Medium Saved from URL mark to assure Internet zone processing must be enforced.
- V-242141 Medium Configuration for file validation must be enforced.
- V-242142 Medium Files from the Internet zone must be opened in Protected View.
- V-242143 Medium Navigation to URL's embedded in Office products must be blocked.
- V-242144 Medium Scripted Window Security must be enforced.
- V-242145 Medium Add-on Management functionality must be allowed.
- V-242146 Medium Application add-ins must be signed by Trusted Publisher.
- V-242147 Medium Data Execution Prevention must be enforced.
- V-242148 Medium Links that invoke instances of IE from within an Office product must be blocked.
- V-242149 Medium Trust Bar Notifications for unsigned application add-ins must be blocked.
- V-242150 Medium File Downloads must be configured for proper restrictions.
- V-242151 Medium All automatic loading from Trusted Locations must be disabled.
- V-242152 Medium Disallowance of Trusted Locations on the network must be enforced.
- V-242153 Medium Save files default format must be configured.
- V-242154 Medium Force encrypted macros to be scanned in open XML documents must be determined and configured.
- V-242155 Medium Trust access for VBA must be disallowed.
- V-242156 Medium Protection from zone elevation must be enforced.
- V-242157 Medium Pre-release versions of file formats new to Office Products must be blocked.
- V-242158 Medium ActiveX Installs must be configured for proper restriction.
- V-242159 Medium Files in unsafe locations must be opened in Protected View.
- V-242160 Medium The ability to run programs from a PowerPoint presentation must be disallowed.
- V-242161 Medium Hidden markup options must be visible.
- V-242162 Medium Automatic download of linked images must be disallowed.
- V-242163 Medium Document behavior if file validation fails must be set.
- V-242164 Medium Attachments opened from Outlook must be in Protected View.
- V-242165 Medium Warning Bar settings for VBA macros must be configured.
- V-242166 Medium The configuration for Slide Update with counterparts must be disallowed.
- V-265894 High The version of PowerPoint running on the system must be a supported version.
Removed rules 31
- V-17173 Medium Disabling of user name and password syntax from being used in URLs must be enforced.
- V-17174 Medium Enabling IE Bind to Object functionality must be present.
- V-17175 Medium Saved from URL mark to assure Internet zone processing must be enforced.
- V-17183 Medium Navigation to URL's embedded in Office products must be blocked.
- V-17184 Medium Links that invoke instances of IE from within an Office product must be blocked.
- V-17187 Medium Trust Bar Notifications for unsigned application add-ins must be blocked.
- V-17322 Medium Pre-release versions of file formats new to Office Products must be blocked.
- V-17471 Medium All automatic loading from Trusted Locations must be disabled.
- V-17473 Medium Force encrypted macros to be scanned in open XML documents must be determined and configured.
- V-17520 Medium Disallowance of Trusted Locations on the network must be enforced.
- V-17521 Medium Save files default format must be configured.
- V-17522 Medium Trust access for VBA must be disallowed.
- V-17545 Medium Warning Bar settings for VBA macros must be configured.
- V-17752 Medium Hidden markup options must be visible.
- V-17788 Medium The ability to run programs from a PowerPoint presentation must be disallowed.
- V-17809 Medium Automatic download of linked images must be disallowed.
- V-26584 Medium Add-on Management functionality must be allowed.
- V-26585 Medium Protection from zone elevation must be enforced.
- V-26586 Medium ActiveX Installs must be configured for proper restriction.
- V-26587 Medium File Downloads must be configured for proper restrictions.
- V-26588 Medium Scripted Window Security must be enforced.
- V-26589 Medium Application add-ins must be signed by Trusted Publisher.
- V-26590 Medium Data Execution Prevention must be enforced.
- V-26592 Medium Configuration for file validation must be enforced.
- V-26612 Medium Blocking as default file block opening behavior must be enforced.
- V-26614 Medium Files from the Internet zone must be opened in Protected View.
- V-26615 Medium Files in unsafe locations must be opened in Protected View.
- V-26616 Medium Document behavior if file validation fails must be set.
- V-26617 Medium Attachments opened from Outlook must be in Protected View.
- V-26625 Medium Disable UI extending from documents and templates must be disallowed.
- V-26639 Medium The configuration for Slide Update with counterparts must be disallowed.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO104 - PowerPoint
- Vuln IDs
-
- V-242137
- V-17173
- Rule IDs
-
- SV-242137r961092_rule
- SV-33406
Checks: C-45412r709868_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Disable user name and password" must be "Enabled" and a check in the "powerpnt.exe" and "pptview.exe" check boxes must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45370r709869_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Disable user name and password" to "Enabled" and place a check in the "powerpnt.exe" and "pptview.exe" check boxes.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTOO110 - PowerPoint
- Vuln IDs
-
- V-242138
- V-26612
- Rule IDs
-
- SV-242138r961086_rule
- SV-33933
Checks: C-45413r709871_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> File Block Settings "Set default file block behavior" must be "Enabled: Blocked files are not opened". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\fileblock Criteria: If the value OpenInProtectedView is REG_DWORD = 0, this is not a finding.
Fix: F-45371r709872_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> File Block Settings "Set default file block behavior" to "Enabled: Blocked files are not opened".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- DTOO111 - PowerPoint
- Vuln IDs
-
- V-242139
- V-17174
- Rule IDs
-
- SV-242139r960921_rule
- SV-33389
Checks: C-45414r709874_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Bind to Object" must be "Enabled" and a check in the "powerpnt.exe" and "pptview.exe" check boxes must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45372r709875_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Bind to Object" to "Enabled" and place a check in the "powerpnt.exe" and "pptview.exe" check boxes.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO117 - PowerPoint
- Vuln IDs
-
- V-242140
- V-17175
- Rule IDs
-
- SV-242140r961092_rule
- SV-33417
Checks: C-45415r709877_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Saved from URL" must be "Enabled" and a check in the "powerpnt.exe" and "pptview.exe" check boxes must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45373r709878_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Saved from URL" to "Enabled"and place a check in the "powerpnt.exe" and "pptview.exe" check boxes.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- DTOO119 - PowerPoint
- Vuln IDs
-
- V-242141
- V-26592
- Rule IDs
-
- SV-242141r960921_rule
- SV-33935
Checks: C-45416r709880_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Turn off file validation" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\filevalidation Criteria: If the value EnableOnLoad is REG_DWORD = 1, this is not a finding.
Fix: F-45374r709881_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Turn off file validation" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTOO121 - PowerPoint
- Vuln IDs
-
- V-242142
- V-26614
- Rule IDs
-
- SV-242142r961086_rule
- SV-33862
Checks: C-45417r709883_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View "Do not open files from the Internet zone in Protected View" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\protectedview Criteria: If the value DisableInternetFilesInPV is REG_DWORD = 0, this is not a finding.
Fix: F-45375r709958_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View "Do not open files from the Internet zone in Protected View" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO123 - PowerPoint
- Vuln IDs
-
- V-242143
- V-17183
- Rule IDs
-
- SV-242143r961092_rule
- SV-33413
Checks: C-45418r709886_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Navigate URL" must be "Enabled" and a check in the "powerpnt.exe" and "pptview.exe" check boxes must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45376r709887_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Navigate URL" to "Enabled"and place a check in the "powerpnt.exe" and "pptview.exe" check boxes.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- DTOO124 - PowerPoint
- Vuln IDs
-
- V-242144
- V-26588
- Rule IDs
-
- SV-242144r960921_rule
- SV-33804
Checks: C-45419r709889_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Scripted Window Security Restrictions" must be set to "Enabled" and "powerpnt.exe" and "pptview.exe" are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45377r709890_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Scripted Window Security Restrictions" to "Enabled" and "powerpnt.exe" and "pptview.exe" are checked.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTOO126 - PowerPoint
- Vuln IDs
-
- V-242145
- V-26584
- Rule IDs
-
- SV-242145r961086_rule
- SV-33784
Checks: C-45420r709892_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Add-on Management" must be set to "Enabled" and "powerpnt.exe" and "pptview.exe" are checked. Procedure: Use the Windows Registry Editor to navigate to the following keys: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45378r709893_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Add-on Management" to "Enabled" and "powerpnt.exe" and "pptview.exe" are checked.
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001749
- Version
- DTOO127 - PowerPoint
- Vuln IDs
-
- V-242146
- V-26589
- Rule IDs
-
- SV-242146r960954_rule
- SV-33852
Checks: C-45421r709895_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "Require that application add-ins are signed by Trusted Publisher" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value RequireAddinSig is REG_DWORD = 1, this is not a finding.
Fix: F-45379r709896_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "Require that application add-ins are signed by Trusted Publisher" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO128 - PowerPoint
- Vuln IDs
-
- V-242147
- V-26590
- Rule IDs
-
- SV-242147r961092_rule
- SV-33858
Checks: C-45422r709898_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "Turn off Data Execution Prevention" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value EnableDEP is REG_DWORD = 1, this is not a finding.
Fix: F-45380r709899_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "Turn off Data Execution Prevention" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTOO129 - PowerPoint
- Vuln IDs
-
- V-242148
- V-17184
- Rule IDs
-
- SV-242148r961086_rule
- SV-33395
Checks: C-45423r709901_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Block popups" must be "Enabled" and "powerpnt.exe" and "pptview.exe" are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45381r709902_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Block popups" to "Enabled" and select "powerpnt.exe" and "pptview.exe".
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001749
- Version
- DTOO131 - PowerPoint
- Vuln IDs
-
- V-242149
- V-17187
- Rule IDs
-
- SV-242149r960954_rule
- SV-33604
Checks: C-45424r709904_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "Disable Trust Bar Notification for unsigned application add-ins and block them" must be "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value NoTBPromptUnsignedAddin is REG_DWORD = 1, this is not a finding.
Fix: F-45382r709905_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "Disable Trust Bar Notification for unsigned application add-ins and block them" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001169
- Version
- DTOO132 - PowerPoint
- Vuln IDs
-
- V-242150
- V-26587
- Rule IDs
-
- SV-242150r961089_rule
- SV-33802
Checks: C-45425r709907_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Restrict File Download" must be set to "Enabled" and "powerpnt.exe" and "pptview.exe" are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45383r709908_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Restrict File Download" to "Enabled" and "powerpnt.exe" and "pptview.exe" are checked.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO133 - PowerPoint
- Vuln IDs
-
- V-242151
- V-17471
- Rule IDs
-
- SV-242151r961092_rule
- SV-33608
Checks: C-45426r709910_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations "Disable all trusted locations" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\trusted locations Criteria: If the value AllLocationsDisabled is REG_DWORD = 1, this is not a finding.
Fix: F-45384r709911_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations "Disable all trusted locations" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO134 - PowerPoint
- Vuln IDs
-
- V-242152
- V-17520
- Rule IDs
-
- SV-242152r961092_rule
- SV-33607
Checks: C-45427r709913_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations "Allow Trusted Locations on the network" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\trusted locations Criteria: If the value AllowNetworkLocations is REG_DWORD = 0, this is not a finding.
Fix: F-45385r709914_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations "Allow Trusted Locations on the network" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO139 - PowerPoint
- Vuln IDs
-
- V-242153
- V-17521
- Rule IDs
-
- SV-242153r960963_rule
- SV-33599
Checks: C-45428r709916_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Save "default file format" must be set to "Enabled PowerPoint Presentation (*.pptx)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\options Criteria: If the value DefaultFormat is REG_DWORD = 1b (hex) 27 (dec) , this is not a finding.
Fix: F-45386r709917_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Save "default file format" to "Enabled PowerPoint Presentation (*.pptx)".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO142 - PowerPoint
- Vuln IDs
-
- V-242154
- V-17473
- Rule IDs
-
- SV-242154r961092_rule
- SV-33602
Checks: C-45429r709919_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Scan encrypted macros in PowerPoint Open XML presentations" must be "Enabled (Scan encrypted macros (default)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value PowerPointBypassEncryptedMacroScan is REG_DWORD = 0, this not a finding.
Fix: F-45387r709920_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Scan encrypted macros in PowerPoint Open XML presentations" to "Enabled (Scan encrypted macros (default)".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO146 - PowerPoint
- Vuln IDs
-
- V-242155
- V-17522
- Rule IDs
-
- SV-242155r960963_rule
- SV-33605
Checks: C-45430r709922_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "Trust access to Visual Basic Project" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value AccessVBOM is REG_DWORD=0, this is not a finding.
Fix: F-45388r709923_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "Trust access to Visual Basic Project" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- DTOO209 - PowerPoint
- Vuln IDs
-
- V-242156
- V-26585
- Rule IDs
-
- SV-242156r960921_rule
- SV-33787
Checks: C-45431r709925_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Protection From Zone Elevation" must be set to "Enabled"and "powerpnt.exe" and "pptview.exe" are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45389r709926_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Protection From Zone Elevation" to "Enabled" and "powerpnt.exe" and "pptview.exe" are checked.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-001764
- Version
- DTOO210 - PowerPoint
- Vuln IDs
-
- V-242157
- V-17322
- Rule IDs
-
- SV-242157r961473_rule
- SV-33449
Checks: C-45432r709928_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office 2010 Converters "Block opening of pre-release versions of file formats new to PowerPoint 2010 through the Compatibility Pack for Office 2010 and PowerPoint 2010 Converter" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\fileblock Criteria: If the value PowerPoint12BetaFilesFromConverters is REG_DWORD = 1, this is not a finding.
Fix: F-45390r709929_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office 2010 Converters "Block opening of pre-release versions of file formats new to PowerPoint 2010 through the Compatibility Pack for Office 2010 and PowerPoint 2010 Converter" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-002460
- Version
- DTOO211 - PowerPoint
- Vuln IDs
-
- V-242158
- V-26586
- Rule IDs
-
- SV-242158r961779_rule
- SV-33796
Checks: C-45433r709931_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Restrict ActiveX Install" must be set to "Enabled" and "powerpnt.exe" and "pptview.exe" are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-45391r709932_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security "Restrict ActiveX Install" to "Enabled" and "powerpnt.exe" and "pptview.exe" are checked.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO288 - PowerPoint
- Vuln IDs
-
- V-242159
- V-26615
- Rule IDs
-
- SV-242159r961092_rule
- SV-33866
Checks: C-45434r709934_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View "Do not open files in unsafe locations in Protected View" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\protectedview Criteria: If the value DisableUnsafeLocationsInPV is REG_DWORD = 0, this is not a finding.
Fix: F-45392r709935_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View "Do not open files in unsafe locations in Protected View" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO289 - PowerPoint
- Vuln IDs
-
- V-242160
- V-17788
- Rule IDs
-
- SV-242160r961092_rule
- SV-33601
Checks: C-45435r709937_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Run Programs" must be "Enabled (disable - (don't run any programs))". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value RunPrograms is REG_DWORD = 0, this is not a finding.
Fix: F-45393r709938_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Run Programs" to "Enabled (disable - (don't run any programs))".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO290 - PowerPoint
- Vuln IDs
-
- V-242161
- V-17752
- Rule IDs
-
- SV-242161r961863_rule
- SV-33600
Checks: C-45436r709940_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Make hidden markup visible" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\options Criteria: If the value MarkupOpenSave is REG_DWORD = 1, this is not a finding.
Fix: F-45394r709941_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Make hidden markup visible" to "Enabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001169
- Version
- DTOO291 - PowerPoint
- Vuln IDs
-
- V-242162
- V-17809
- Rule IDs
-
- SV-242162r961089_rule
- SV-33603
Checks: C-45437r709943_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Unblock automatic download of linked images" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value DownloadImages is REG_DWORD = 0, this is not a finding.
Fix: F-45395r709944_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security "Unblock automatic download of linked images" to "Disabled".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO292 - PowerPoint
- Vuln IDs
-
- V-242163
- V-26616
- Rule IDs
-
- SV-242163r961092_rule
- SV-33869
Checks: C-45438r709946_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View "Set document behavior if file validation fails" must be "Enabled: Open in Protected View" and Unchecked for "Do not allow edit". Procedure: Use the Windows Registry Editor to navigate to the following keys: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\filevalidation Criteria: If the value OpenInProtectedView is REG_DWORD = 1, this is not a finding. AND HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\filevalidation Criteria: If the value DisableEditFromPV is REG_DWORD = 1, this is not a finding.
Fix: F-45396r709947_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View "Set document behavior if file validation fails" to "Enabled: Open in Protected View" and Unchecked for "Do not allow edit".
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTOO293 - PowerPoint
- Vuln IDs
-
- V-242164
- V-26617
- Rule IDs
-
- SV-242164r961092_rule
- SV-33876
Checks: C-45439r709949_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View "Turn off Protected View for attachments opened from Outlook" must be set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\protectedview Criteria: If the value DisableAttachmentsInPV is REG_DWORD = 0, this is not a finding.
Fix: F-45397r709950_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View "Turn off Protected View for attachments opened from Outlook" to "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTOO304 - PowerPoint
- Vuln IDs
-
- V-242165
- V-17545
- Rule IDs
-
- SV-242165r960963_rule
- SV-33606
Checks: C-45440r709952_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "VBA Macro Notification Settings" must be "Enabled (Disable all with notification)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value VBAWarnings is REG_DWORD = 2, this is not a finding.
Fix: F-45398r709953_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center "VBA Macro Notification Settings" to "Enabled (Disable all with notification)".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO319 - PowerPoint
- Vuln IDs
-
- V-242166
- V-26639
- Rule IDs
-
- SV-242166r961863_rule
- SV-34090
Checks: C-45441r709955_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> Miscellaneous "Disable Slide Update" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\slide libraries Criteria: If the value DisableSlideUpdate is REG_DWORD = 1, this is not a finding.
Fix: F-45399r709956_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> Miscellaneous "Disable Slide Update" to "Enabled".
- RMF Control
- SI-2
- Severity
- H
- CCI
- CCI-002605
- Version
- DTOO999 - PowerPoint
- Vuln IDs
-
- V-265894
- Rule IDs
-
- SV-265894r999886_rule
Checks: C-69813r999884_chk
PowerPoint 2010 is no longer supported by the vendor. If the system is running PowerPoint 2010, this is a finding.
Fix: F-69717r999885_fix
Upgrade to a supported version.