[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Untrusted Font Blocking

ID: oval:org.secpod.oval:def:40189Date: (C)2017-04-25   (M)2023-07-04
Class: COMPLIANCEFamily: windows




This security feature provides a global setting to prevent programs from loading untrusted fonts. Untrusted fonts are any font installed outside of the %windir%\Fonts directory. This feature can be configured to be in 3 modes: On, Off, and Audit. By default, it is Off and no fonts are blocked. If you aren't quite ready to deploy this feature into your organization, you can run it in Audit mode to see if blocking untrusted fonts causes any usability or compatibility issues. Vulnerability: Disabling or not configuring this setting can compromise security as it may allow a malicious agent to load an unprotected font via an Office application or web browser. Counter Measure: Enable and configure this setting depending on your organization's requirements. Potential Impact: Some applications may not be compatible with blocking untrusted fonts. Fix: (1) GPO: Computer Configuration\Administrative Templates\System\Mitigation Options\Untrusted Font Blocking (2) REG: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\MitigationOptions!MitigationOptions_FontBocking

Platform:
Microsoft Windows Server 2016
Reference:
CCE-45231-8
CPE    1
cpe:/o:microsoft:windows_server_2016:::x64
CCE    1
CCE-45231-8
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_Server_2016

© SecPod Technologies