WNDF-AV-000035 - Windows Defender AV must be configured to block Office applications from injecting into other processes.

Information

Office apps, such as Word, Excel, or PowerPoint, will not be able to inject code into other processes. This is typically used by malware to run malicious code in an attempt to hide the activity from antivirus scanning engines.

Solution

Set the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Defender Antivirus -> Windows Defender Exploit Guard -> Attack Surface Reduction -> 'Configure Attack Surface Reduction rules' to 'Enabled'. Click 'Show...'. Set the Value name to '75668C1F-73B5-4CF0-BB93-3ECF5CB7CC84' and the Value to '1'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Defender_Antivirus_V1R9_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CAT|II, CCI|CCI-001170, Rule-ID|SV-92667r1_rule, STIG-ID|WNDF-AV-000035, Vuln-ID|V-77971

Plugin: Windows

Control ID: 7d4c2d1a4bd92096b447b61ff42ab74298bd992dcb1f6ef1f307b8eec246720c