Free DISA STIG and SRG Library | Vaulted

ADBP-XI-001005

Adobe Acrobat Pro XI Enhanced Security for browser mode must be enabled.

Finding ID
ADBP-XI-001005
Rule ID
ADBP-XI-001005_rule
Severity
Cat II
CCE
(None)
Group Title
SRG-APP-000431
CCI
CCI-002530
Target Key
(None)
Documentable
No
Discussion

Enhanced Security (ES) is a sandbox capability that restricts access to system resources and prevents PDF cross-domain access. ES can be configured in two modes: Standalone mode is when Acrobat opens the desktop PDF client. ES Browser mode is when a PDF is opened via the browser plugin. When Enhanced Security is enabled and a PDF file tries to complete a restricted action from an untrusted location, a security warning must appear. Enhanced Security “hardens” the application against risky actions. It prevents cross-domain access, prohibits script and data injection, and blocks stream access to XObjects, silent printing, and execution of high-privilege JavaScript.

Fix Text

Configure the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Adobe\Adobe Acrobat\11.0\FeatureLockDown Value Name: bEnhancedSecurityInBrowser Type: REG_DWORD Value: 1

Check Content

Verify the following registry configuration: Using the Registry Editor, navigate to the following: HKEY_LOCAL_MACHINE\Software\Policies\Adobe\Adobe Acrobat\11.0\FeatureLockDown Value Name: bEnhancedSecurityInBrowser Type: REG_DWORD Value: 1 If the value for bEnhancedSecurityInBrowser is not set to “1” and Type is not configured to REG_DWORD or does not exist, this is a finding.