CCE-427-5Platform: office2k7 | Date: (C)2010-04-28 (M)2022-10-10 |
The "VBA Macro Warning Settings" setting should be configured correctly for Access 2007.
Parameter:
(1) 1 = No Security checks for macros | 2 = Trust Bar warning for all macros | 3 = Trust Bar warning for digitally signed macros only | 4 = No Warnings for all macros but disable all macros
Technical Mechanism:
(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Access 2007 / Application Settings / Security / Trust Center
(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Access\Security\VBAWarnings
CCSS Severity: | CCSS Metrics: |
CCSS Score : | Attack Vector: |
Exploit Score: | Attack Complexity: |
Impact Score: | Privileges Required: |
Severity: | User Interaction: |
Vector: | Scope: |
| Confidentiality: |
| Integrity: |
| Availability: |
| |
References: Resource Id | Reference |
---|
Old v4 CCE ID | CCE-427 |
Microsoft Office 2007 Threats and Countermeasures guide Beta release | Table 1.234. VBA Macro Warning Settings |
Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx) | User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\VBA Macro Warning Settings (Trust Bar warning for all macros \| Trust Bar warning for digitally signed macros only (unsigned macros will be disabled) \| No Warnings for all macros but disable all macros \| No Security checks for macros (Not recommended, code in all documents can run)) |
NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml) | oval:org.mitre.oval:def:1403 |
NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml ) | VBAMacroWarningSettings-Access |
Microsoft Office 2007 DISA STIGs | STIG ID: DTOO304 - Access Rule ID: SV-18637r2_rule Vuln ID: V-17545: Enable Warning Bar settings for VBA macros contained in Access Files. |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:11631 |
BITS Shared Assessments SIG v6.0 | BITS Shared Assessments SIG v6.0 |
Jericho Forum | Jericho Forum |
HIPAA/HITECH Act | HIPAA/HITECH Act |
FedRAMP Security Controls(Final Release Jan 2012)--LOW IMPACT LEVEL-- | FedRAMP Security Controls(Final Release Jan 2012)--LOW IMPACT LEVEL-- |
ISO/IEC 27001-2005 | ISO/IEC 27001-2005 |
COBIT 4.1 | COBIT 4.1 |
GAPP (Aug 2009) | GAPP (Aug 2009) |
NERC CIP | NERC CIP |
NIST SP800-53 R3 | NIST SP800-53 R3 CM-6 |
NIST SP800-53 R3 | NIST SP800-53 R3 CM-7 |
PCIDSS v2.0 | PCIDSS v2.0 |
FedRAMP Security Controls(Final Release Jan 2012)--MODERATE IMPACT LEVEL-- | FedRAMP Security Controls(Final Release Jan 2012)--MODERATE IMPACT LEVEL-- |
BITS Shared Assessments AUP v5.0 | BITS Shared Assessments AUP v5.0 |