UCF STIG Viewer Logo

File types must be configured to provide mismatch warnings


Overview

Finding ID Version Rule ID IA Controls Severity
V-17621 DTOO143 SV-53811r1_rule Medium
Description
Excel can load files with extensions that do not match the files' type. For example, if a comma-separated values (CSV) file named example.csv is renamed example.xls, Excel can properly load it as a CSV file. Some attacks target specific file formats. If Excel is allowed to load files with extensions that do not match their file types, a malicious individual can deceive users into loading dangerous files that have incorrect extensions. By default, if users attempt to open files with the wrong extension, Excel opens the file and displays a warning that the file type is not what Excel expected.
STIG Date
Microsoft Excel 2013 STIG 2018-04-03

Details

Check Text ( C-47883r1_chk )
Verify the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2013 -> Excel Options -> Security "Force file extension to match file type" is set to "Enabled (Allow different, but warn)".

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\15.0\excel\security

Criteria: If the value ExtensionHardening is REG_DWORD = 1, this is not a finding.
Fix Text (F-46720r1_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2013 -> Excel Options -> Security "Force file extension to match file type" to "Enabled (Allow different, but warn)".