Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-17519 | DTOO154 - Excel | SV-18595r1_rule | ECSC-1 | Medium |
Description |
---|
The Office Open XML format file types introduced in the 2007 Microsoft Office release offer a number of benefits compared to the previous binary file types supported in Office 2003, including the potential to reduce the effects of malicious code. Files can be identified as unable to run code, and will therefore ignore any embedded code. Also, any files that do have embedded code are easier to identify. If a vulnerability is discovered that affects Office Open XML files, you can use this setting to protect your organization against attacks by temporarily preventing users from opening files in these formats until a security patch is available. |
STIG | Date |
---|---|
Microsoft Excel 2007 | 2015-10-02 |
Check Text ( C-18838r1_chk ) |
---|
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of Open XML file types” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock Criteria: If the value OpenXmlFiles is REG_DWORD = 0, this is not a finding. |
Fix Text (F-17438r1_fix) |
---|
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open “Block opening of Open XML file types” will be set to “Disabled”. |