Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-17759 | DTOO179 - Office System | SV-33480r1_rule | ECSC-1 | Medium |
Description |
---|
Office document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode. However, if the default configuration is changed, the document is opened as read/write. Users could potentially make changes to documents and resave them in situations where the Web server security is not configured to prevent such changes. |
STIG | Date |
---|---|
Microsoft Office System 2010 | 2012-06-22 |
Check Text ( C-33963r1_chk ) |
---|
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... -> Files “Open Office documents as read/write while browsing” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\internet Criteria: If the value OpenDocumentsReadWriteWhileBrowsing is REG_DWORD = 0, this is not a finding. |
Fix Text (F-29652r1_fix) |
---|
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Tools \ Options \ General \ Web Options... -> Files “Open Office documents as read/write while browsing” to “Disabled”. |