Adobe Acrobat Reader DC Continuous Track Security Technical Implementation Guide

Overview

VersionDateFinding Count (26)Downloads
22021-06-22CAT I (High): 1CAT II (Medium): 16CAT III (Low): 9
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.
ClassifiedPublicSensitive
I - Mission Critical ClassifiedI - Mission Critical PublicI - Mission Critical Sensitive
II - Mission Support ClassifiedII - Mission Support PublicII - Mission Support Sensitive
III - Administrative ClassifiedIII - Administrative PublicIII - Administrative Sensitive

Findings - All

Finding IDSeverityTitleDescription
V-213192
LOWMEDIUMHIGH
Adobe Reader DC must have the latest Security-related Software Updates installed.Security flaws with software applications are discovered daily. Vendors are constantly updating and patching their products to address newly discovere...
V-213168
LOWMEDIUMHIGH
Adobe Reader DC must enable Enhanced Security in a Standalone Application.PDFs have evolved from static pages to complex documents with features such as interactive forms, multimedia content, scripting, and other capabilitie...
V-213169
LOWMEDIUMHIGH
Adobe Reader DC must enable Enhanced Security in a Browser.PDFs have evolved from static pages to complex documents with features such as interactive forms, multimedia content, scripting, and other capabilitie...
V-213170
LOWMEDIUMHIGH
Adobe Reader DC must enable Protected Mode.A threat to users of Adobe Reader DC is opening a PDF file that contains malicious executable content. Protected mode provides a sandbox capability t...
V-213171
LOWMEDIUMHIGH
Adobe Reader DC must enable Protected View.A threat to users of Adobe Reader DC is opening a PDF file that contains malicious executable content. Protected view restricts Adobe Reader DC funct...
V-213172
LOWMEDIUMHIGH
Adobe Reader DC must Block Websites.Clicking any link to the Internet poses a potential security risk. Malicious websites can transfer harmful content or silently gather data. Acrobat Re...
V-213173
LOWMEDIUMHIGH
Adobe Reader DC must block access to Unknown Websites.Because Internet access is a potential security risk, clicking any unknown website link to the Internet poses a potential security risk. Malicious we...
V-213174
LOWMEDIUMHIGH
Adobe Reader DC must prevent opening files other than PDF or FDF.Attachments represent a potential security risk because they can contain malicious content, open other dangerous files, or launch applications. Certai...
V-213175
LOWMEDIUMHIGH
Adobe Reader DC must block Flash Content.Flash content is commonly hosted on a web page, but it can also be embedded in PDF and other documents. Flash could be used to surreptitious install m...
V-213178
LOWMEDIUMHIGH
Adobe Reader DC must disable all service access to Document Cloud Services.By default, Adobe online services are tightly integrated in Adobe Reader DC. With the integration of Adobe Document Cloud, disabling this feature prev...
V-213179
LOWMEDIUMHIGH
Adobe Reader DC must disable Cloud Synchronization.By default, Adobe online services are tightly integrated in Adobe Reader DC. When the Adobe Cloud synchronization is disabled it prevents the synchron...
V-213181
LOWMEDIUMHIGH
Adobe Reader DC must disable 3rd Party Web Connectors.When 3rd Party Web Connectors are disabled it prevents the configuration of Adobe Reader DC access to third party services for file storage....
V-213184
LOWMEDIUMHIGH
Adobe Reader DC must disable access to Webmail.When Webmail is disabled the user cannot configure a webmail account to send an open PDF document as an attachment. Users should have the ability to s...
V-213185
LOWMEDIUMHIGH
Adobe Reader DC must disable Online SharePoint Access.Disabling SharePoint disables or removes the user’s ability to add a SharePoint account access controls the application's ability to detect that a fil...
V-213188
LOWMEDIUMHIGH
Adobe Reader DC must disable the ability to add Trusted Files and Folders.Privileged Locations allow the user to selectively trust files, folders, and hosts to bypass some security restrictions, such as enhanced security and...
V-213189
LOWMEDIUMHIGH
Adobe Reader DC must disable the ability to elevate IE Trusts to Privileged Locations.Privileged Locations allow the user to selectively trust files, folders, and hosts to bypass some security restrictions, such as enhanced security and...
V-213193
LOWMEDIUMHIGH
Adobe Reader DC must enable FIPS mode.Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data. The application must implement cryptogr...
V-213176
LOWMEDIUMHIGH
Adobe Reader DC must disable the ability to change the Default Handler.Allowing user to make changes to an application case cause a security risk. When the Default PDF Handler is disabled, the end users will not be able ...
V-213177
LOWMEDIUMHIGH
Adobe Reader DC must disable the Adobe Send and Track plugin for Outlook.When enabled, Adobe Send and Track button appears in Outlook. When an email is composed it enables the ability to send large files as public links thr...
V-213180
LOWMEDIUMHIGH
Adobe Reader DC must disable the Adobe Repair Installation.When Repair Installation is disabled the user does not have the option (Help Menu) or functional to repair an Adobe Reader DC install....
V-213182
LOWMEDIUMHIGH
Adobe Reader DC must disable Acrobat Upsell.Products that don't provide the full set of features by default provide the user the opportunity to upgrade. Acrobat Upsell displays message which enc...
V-213183
LOWMEDIUMHIGH
Adobe Reader DC must disable Adobe Send for Signature.The Adobe Document Cloud sign service allows users to send documents online for signature and sign from anywhere or any device. The signed documents a...
V-213186
LOWMEDIUMHIGH
Adobe Reader DC must disable the Adobe Welcome Screen.The Adobe Reader DC Welcome screen can be distracting and also has online links to the Adobe quick tips website, tutorials, blogs and community forums...
V-213187
LOWMEDIUMHIGH
Adobe Reader DC must disable Service Upgrades.By default, Adobe online services are tightly integrated into Adobe Reader DC. Disabling Service Upgrades disables both updates to the product's web-p...
V-213190
LOWMEDIUMHIGH
Adobe Reader DC must disable periodical uploading of European certificates.By default, the user can update European certificates from an Adobe server through the GUI. When uploading European certificates is disabled, it prev...
V-213191
LOWMEDIUMHIGH
Adobe Reader DC must disable periodical uploading of Adobe certificates.By default, the user can update Adobe certificates from an Adobe server through the GUI. When uploading Adobe certificates is disabled, it prevents t...