ADBP-XI-000290 - Adobe Acrobat Pro XI must be configured to block Flash Content.

Information

Flash has a long history of vulnerabilities. Although Flash is no longer provided with Acrobat, if the system has Flash installed, a malicious PDF could execute code on the system. Configuring Flash to run from a privileged location limits the execution capability of untrusted Flash content that may be embedded in the PDF.

Solution

Configure the following registry value:

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \Software\Policies\Adobe\Adobe Acrobat\11.0\FeatureLockDown\

Value Name: bEnableFlash
Type: REG_DWORD
Value: 0

See Also

https://iasecontent.disa.mil/stigs/zip/U_Adobe_Acrobat_Pro_XI_V1R2_STIG.zip