Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-26595 | DTOO122 | SV-53678r2_rule | ECSC-1 | Medium |
Description |
---|
This setting specifies whether users can open, view, edit, or save files saved in the specified format. Enabling block of the specified format mitigates zero-day security attacks (which are attacks that occur during between the time that a vulnerability becomes publicly known and a software update or service pack is available) by temporarily preventing users from opening specific types of files and to prevent a user from opening files that have been saved in earlier and pre-release (beta) Microsoft Office formats. |
STIG | Date |
---|---|
Microsoft Excel 2013 STIG | 2015-07-24 |
Check Text ( None ) |
---|
None |
Fix Text (F-46603r1_fix) |
---|
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2013 -> Excel Options -> Security -> Trust Center -> File Block Settings "dBase III / IV files" to "Enabled: Open/Save blocked, use open policy". |