Microsoft PowerPoint 2010
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates No substantive changes
Comparison against the immediately-prior release (V1R8). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
No substantive changes detected against the previous release. 31 rules matched cleanly.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO104 - PowerPoint
- Vuln IDs
-
- V-17173
- Rule IDs
-
- SV-33406r1_rule
Checks: C-33889r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Disable user name and password” must be “Enabled” and a check in the ‘powerpnt.exe’ and 'pptview.exe' check boxes must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29578r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Disable user name and password” to “Enabled” and place a check in the ‘powerpnt.exe’ and 'pptview.exe' check boxes.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO111 - PowerPoint
- Vuln IDs
-
- V-17174
- Rule IDs
-
- SV-33389r1_rule
Checks: C-33872r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Bind to Object” must be “Enabled” and a check in the ‘powerpnt.exe’ and ‘pptview.exe’ check boxes must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29561r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Bind to Object” to “Enabled” and place a check in the ‘powerpnt.exe’ and 'pptview.exe' check boxes.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO117 - PowerPoint
- Vuln IDs
-
- V-17175
- Rule IDs
-
- SV-33417r1_rule
Checks: C-33900r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Saved from URL” must be “Enabled” and a check in the ‘powerpnt.exe’ and 'pptview.exe' check boxes must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29589r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Saved from URL” to “Enabled” and place a check in the ‘powerpnt.exe’ and 'pptview.exe' check boxes.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO123 - PowerPoint
- Vuln IDs
-
- V-17183
- Rule IDs
-
- SV-33413r1_rule
Checks: C-33896r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Navigate URL” must be “Enabled” and a check in the ‘powerpnt.exe’ and 'pptview.exe' check boxes must be present. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29585r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Navigate URL” to “Enabled” and place a check in the ‘powerpnt.exe’ and 'pptview.exe' check boxes.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO129 - PowerPoint
- Vuln IDs
-
- V-17184
- Rule IDs
-
- SV-33395r1_rule
Checks: C-33879r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Block popups” must be “Enabled” and ‘powerpnt.exe’ and ‘pptview.exe’ are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29568r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Block popups” to “Enabled” and select ‘powerpnt.exe’ and ‘pptview.exe’.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO131 - PowerPoint
- Vuln IDs
-
- V-17187
- Rule IDs
-
- SV-33604r1_rule
Checks: C-34069r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins and block them” must be “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value NoTBPromptUnsignedAddin is REG_DWORD = 1, this is not a finding.
Fix: F-29746r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “Disable Trust Bar Notification for unsigned application add-ins and block them” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO210 - PowerPoint
- Vuln IDs
-
- V-17322
- Rule IDs
-
- SV-33449r1_rule
Checks: C-33932r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office 2010 Converters “Block opening of pre-release versions of file formats new to PowerPoint 2010 through the Compatibility Pack for Office 2010 and PowerPoint 2010 Converter” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\fileblock Criteria: If the value PowerPoint12BetaFilesFromConverters is REG_DWORD = 1, this is not a finding.
Fix: F-29621r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Office 2010 Converters “Block opening of pre-release versions of file formats new to PowerPoint 2010 through the Compatibility Pack for Office 2010 and PowerPoint 2010 Converter” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO133 - PowerPoint
- Vuln IDs
-
- V-17471
- Rule IDs
-
- SV-33608r1_rule
Checks: C-34073r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations “Disable all trusted locations” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\trusted locations Criteria: If the value AllLocationsDisabled is REG_DWORD = 1, this is not a finding.
Fix: F-29750r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations “Disable all trusted locations” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO142 - PowerPoint
- Vuln IDs
-
- V-17473
- Rule IDs
-
- SV-33602r1_rule
Checks: C-34067r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Scan encrypted macros in PowerPoint Open XML presentations” must be “Enabled (Scan encrypted macros (default)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value PowerPointBypassEncryptedMacroScan is REG_DWORD = 0, this not a finding.
Fix: F-29744r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Scan encrypted macros in PowerPoint Open XML presentations” to “Enabled (Scan encrypted macros (default)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO134 - PowerPoint
- Vuln IDs
-
- V-17520
- Rule IDs
-
- SV-33607r1_rule
Checks: C-34072r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations “Allow Trusted Locations on the network" must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\trusted locations Criteria: If the value AllowNetworkLocations is REG_DWORD = 0, this is not a finding.
Fix: F-29749r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Trusted Locations “Allow Trusted Locations on the network" to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO139 - PowerPoint
- Vuln IDs
-
- V-17521
- Rule IDs
-
- SV-33599r1_rule
Checks: C-34063r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Save “default file format” must be set to “Enabled PowerPoint Presentation (*.pptx)". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\options Criteria: If the value DefaultFormat is REG_DWORD = 1b (hex) 27 (dec) , this is not a finding.
Fix: F-29741r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Save “default file format” to “Enabled PowerPoint Presentation (*.pptx)".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO146 - PowerPoint
- Vuln IDs
-
- V-17522
- Rule IDs
-
- SV-33605r1_rule
Checks: C-34070r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “Trust access to Visual Basic Project” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value AccessVBOM is REG_DWORD=0, this is not a finding.
Fix: F-29747r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “Trust access to Visual Basic Project” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO304 - PowerPoint
- Vuln IDs
-
- V-17545
- Rule IDs
-
- SV-33606r1_rule
Checks: C-34071r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “VBA Macro Notification Settings” must be “Enabled (Disable all with notification)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value VBAWarnings is REG_DWORD = 2, this is not a finding.
Fix: F-29748r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “VBA Macro Notification Settings” to “Enabled (Disable all with notification)”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO290 - PowerPoint
- Vuln IDs
-
- V-17752
- Rule IDs
-
- SV-33600r1_rule
Checks: C-34064r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Make hidden markup visible” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\options Criteria: If the value MarkupOpenSave is REG_DWORD = 1, this is not a finding.
Fix: F-29742r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Make hidden markup visible” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO289 - PowerPoint
- Vuln IDs
-
- V-17788
- Rule IDs
-
- SV-33601r1_rule
Checks: C-34065r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Run Programs” must be “Enabled (disable - (don't run any programs))”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value RunPrograms is REG_DWORD = 0, this is not a finding.
Fix: F-29743r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Run Programs” to “Enabled (disable - (don't run any programs))”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO291 - PowerPoint
- Vuln IDs
-
- V-17809
- Rule IDs
-
- SV-33603r1_rule
Checks: C-34068r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Unblock automatic download of linked images” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value DownloadImages is REG_DWORD = 0, this is not a finding.
Fix: F-29745r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Unblock automatic download of linked images” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO126 - PowerPoint
- Vuln IDs
-
- V-26584
- Rule IDs
-
- SV-33784r1_rule
Checks: C-34160r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Add-on Management” must be set to “Enabled” and ‘powerpnt.exe’ and 'pptview.exe' are checked. Procedure: Use the Windows Registry Editor to navigate to the following keys: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29849r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Add-on Management” to “Enabled” and ‘powerpnt.exe’ and 'pptview.exe' are checked.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO209 - PowerPoint
- Vuln IDs
-
- V-26585
- Rule IDs
-
- SV-33787r1_rule
Checks: C-34163r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Protection From Zone Elevation” must be set to “Enabled” and ‘powerpnt.exe’ and 'pptview.exe' are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29852r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Protection From Zone Elevation” to “Enabled” and ‘powerpnt.exe’ and 'pptview.exe' are checked.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO211 - PowerPoint
- Vuln IDs
-
- V-26586
- Rule IDs
-
- SV-33796r1_rule
Checks: C-34171r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Restrict ActiveX Install” must be set to “Enabled” and ‘powerpnt.exe’ and 'pptview.exe' are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29860r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Restrict ActiveX Install” to “Enabled” and ‘powerpnt.exe’ and 'pptview.exe' are checked.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO132 - PowerPoint
- Vuln IDs
-
- V-26587
- Rule IDs
-
- SV-33802r1_rule
Checks: C-34176r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Restrict File Download” must be set to “Enabled" and ‘powerpnt.exe’ and 'pptview.exe' are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29865r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Restrict File Download” to “Enabled" and ‘powerpnt.exe’ and 'pptview.exe' are checked.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO124 - PowerPoint
- Vuln IDs
-
- V-26588
- Rule IDs
-
- SV-33804r1_rule
Checks: C-34178r1_chk
The policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Scripted Window Security Restrictions” must be set to “Enabled” and ‘powerpnt.exe’ and 'pptview.exe' are checked. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS Criteria: If the value powerpnt.exe is REG_DWORD = 1, this is not a finding. AND HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS Criteria: If the value pptview.exe is REG_DWORD = 1, this is not a finding.
Fix: F-29867r1_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Microsoft Office 2010 (Machine) -> Security Settings -> IE Security “Scripted Window Security Restrictions” to “Enabled” and ‘powerpnt.exe’ and 'pptview.exe' are checked.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO127 - PowerPoint
- Vuln IDs
-
- V-26589
- Rule IDs
-
- SV-33852r1_rule
Checks: C-34241r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “Require that application add-ins are signed by Trusted Publisher” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value RequireAddinSig is REG_DWORD = 1, this is not a finding.
Fix: F-29935r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “Require that application add-ins are signed by Trusted Publisher” to “Enabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO128 - PowerPoint
- Vuln IDs
-
- V-26590
- Rule IDs
-
- SV-33858r1_rule
Checks: C-34242r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “Turn off Data Execution Prevention” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security Criteria: If the value EnableDEP is REG_DWORD = 1, this is not a finding.
Fix: F-29936r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center “Turn off Data Execution Prevention” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO119 - PowerPoint
- Vuln IDs
-
- V-26592
- Rule IDs
-
- SV-33935r1_rule
Checks: C-34240r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Turn off file validation” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\filevalidation Criteria: If the value EnableOnLoad is REG_DWORD = 1, this is not a finding.
Fix: F-29934r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security “Turn off file validation” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO110 - PowerPoint
- Vuln IDs
-
- V-26612
- Rule IDs
-
- SV-33933r1_rule
Checks: C-34243r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> File Block Settings “Set default file block behavior” must be “Enabled: Blocked files are not opened”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\fileblock Criteria: If the value OpenInProtectedView is REG_DWORD = 0, this is not a finding.
Fix: F-29937r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> File Block Settings “Set default file block behavior” to “Enabled: Blocked files are not opened”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO121 - PowerPoint
- Vuln IDs
-
- V-26614
- Rule IDs
-
- SV-33862r1_rule
Checks: C-34244r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View “Do not open files from the Internet zone in Protected View” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\protectedview Criteria: If the value DisableInternetFilesInPV is REG_DWORD = 0, this is not a finding.
Fix: F-29938r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View “Do not open files from the Internet zone in Protected View to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO288 - PowerPoint
- Vuln IDs
-
- V-26615
- Rule IDs
-
- SV-33866r1_rule
Checks: C-34245r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View “Do not open files in unsafe locations in Protected View” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\protectedview Criteria: If the value DisableUnsafeLocationsInPV is REG_DWORD = 0, this is not a finding.
Fix: F-29939r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View “Do not open files in unsafe locations in Protected View” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO292 - PowerPoint
- Vuln IDs
-
- V-26616
- Rule IDs
-
- SV-33869r1_rule
Checks: C-34246r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View “Set document behavior if file validation fails” must be "Enabled: Open in Protected View" and Unchecked for "Do not allow edit". Procedure: Use the Windows Registry Editor to navigate to the following keys: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\filevalidation Criteria: If the value OpenInProtectedView is REG_DWORD = 1, this is not a finding. AND HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\filevalidation Criteria: If the value DisableEditFromPV is REG_DWORD = 1, this is not a finding.
Fix: F-29940r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View “Set document behavior if file validation fails” to "Enabled: Open in Protected View" and Unchecked for "Do not allow edit".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO293 - PowerPoint
- Vuln IDs
-
- V-26617
- Rule IDs
-
- SV-33876r1_rule
Checks: C-34247r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View “Turn off Protected View for attachments opened from Outlook” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\security\protectedview Criteria: If the value DisableAttachmentsInPV is REG_DWORD = 0, this is not a finding.
Fix: F-29941r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> PowerPoint Options -> Security -> Trust Center -> Protected View “Turn off Protected View for attachments opened from Outlook” to “Disabled”.
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO305 - PowerPoint
- Vuln IDs
-
- V-26625
- Rule IDs
-
- SV-33813r2_rule
Checks: C-34187r3_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Global Options -> Customize “Disable UI extending from documents and templates” must be “Enabled" and "Disallow in PowerPoint" selected. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\toolbars\powerpoint Criteria: If the value NoExtensibilityCustomizationFromDocument is REG_DWORD = 1, this is not a finding.
Fix: F-29876r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Global Options -> Customize “Disable UI extending from documents and templates” to “Enabled" and select "Disallow in PowerPoint".
- RMF Control
- Severity
- M
- CCI
- Version
- DTOO319 - PowerPoint
- Vuln IDs
-
- V-26639
- Rule IDs
-
- SV-34090r1_rule
Checks: C-34239r1_chk
The policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> Miscellaneous “Disable Slide Update” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\powerpoint\slide libraries Criteria: If the value DisableSlideUpdate is REG_DWORD = 1, this is not a finding.
Fix: F-29933r1_fix
Set the policy value for User Configuration -> Administrative Templates -> Microsoft PowerPoint 2010 -> Miscellaneous “Disable Slide Update” to “Enabled”.