Details
When a separate application is used to launch Publisher 2010 programmatically, any macros can run in the programmatically-opened application without being blocked. Disabling or not configuring this setting could allow a malicious user to use automation to run malicious code in Publisher 2010.
Solution
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Publisher 2010 -> Security ‘Publisher Automation Security Level’ to ‘Enabled and High (Disabled)’ is selected.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Windows.
References
- 800-53|SC-18(4)
- CAT|II
- CCI|CCI-001170
- Rule-ID|SV-34093r1_rule
- STIG-ID|DTOO323
- Vuln-ID|V-26708