UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Disable feature that would block older version of office products from saving files to open XML formats.


Overview

Finding ID Version Rule ID IA Controls Severity
V-17503 DTOO155 - Excel SV-18573r1_rule ECSC-1 Medium
Description
The Office Open XML format file types introduced in the 2007 Microsoft Office release offer a number of benefits compared with the previous binary file types supported in Office 2003, including the potential to reduce the effects of malicious code. Files can be identified as unable to run code, and will therefore ignore any embedded code. Also, any files that do have embedded code are easier to identify. For users who run older versions of these applications, Microsoft offers the Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats, which enables them to open and save Open XML files. The Compatibility Pack can be used with the following Microsoft Office programs: • Word 2000 with Service Pack 3, Excel 2000 with Service Pack 3, and PowerPoint 2000 with Service Pack 3 • Word 2002 with Service Pack 3, Excel 2002 with Service Pack 3, and PowerPoint 2002 with Service Pack 3 • Word 2003 with at least Service Pack 1, Excel 2003 with at least Service Pack 1, and PowerPoint 2003 with at least Service Pack 1 • Microsoft Office Word Viewer 2003 • Microsoft Office Excel Viewer 2003 • Microsoft Office PowerPoint Viewer 2003 If users cannot save files in Office Open XML format for some reason, they will be unable to take advantage of the security benefits of the new file types.
STIG Date
Microsoft Excel 2007 2014-12-22

Details

Check Text ( C-18830r1_chk )
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Save “Block saving of Open XML file types” will be set to “Disabled”.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock

Criteria: If the value OpenXmlFiles is REG_DWORD = 0, this is not a finding.
Fix Text (F-17428r1_fix)
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Save “Block saving of Open XML file types” will be set to “Disabled”.