Hyperlink warnings for Office must be configured for use.

From Microsoft Office System 2010 STIG

Part of DTOO194 - Hyperlink warnings for Office

Associated with: CCI-002460

SV-33469r1_rule Hyperlink warnings for Office must be configured for use.

Vulnerability discussion

Unsafe hyperlinks are links that might pose a security risk if users click them. Clicking an unsafe link could compromise the security of sensitive information or harm the computer.Links that Office considers unsafe include links to executable files, TIFF files, and Microsoft Document Imaging (MDI) files. Other unsafe links are those using protocols considered to be unsafe, including msn, nntp, mms, outlook, and stssync.

Check content

The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Suppress hyperlink warnings” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\common\security Criteria: If the value DisableHyperLinkWarning is REG_DWORD = 0, this is not a finding.

Fix text

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Security Settings “Suppress hyperlink warnings” to “Disabled”.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer