UCF STIG Viewer Logo

Smart Documents use of Manifests in Office must be disallowed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-17669 DTOO197 - Office System SV-33475r1_rule Medium
Description
An XML expansion pack is the group of files that constitutes a Smart Document in Excel and Word. You package one or more components that provide the logic needed for a Smart Document by using an XML expansion pack. These components can include any type of file, including XML schemas, Extensible Stylesheet Language Transforms (XSLTs), dynamic-link libraries (DLLs), and image files, as well as additional XML files, HTML files, Word files, Excel files, and text files. The key component to building an XML expansion pack is creating an XML expansion pack manifest file. By creating this file, you specify the locations of all files that make up the XML expansion pack, as well as information that instructs 2007 Office how to set up the files for your Smart Document. The XML expansion pack can also contain information about how to set up some files, such as how to install and register a COM object required by the XML expansion pack. XML expansion packs can be used to initialize and load malicious code, which might affect the stability of a computer and lead to data loss. Office applications can load an XML expansion pack manifest file with a Smart Document.
STIG Date
Microsoft Office System 2010 STIG 2018-04-04

Details

Check Text ( C-33958r1_chk )
The policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Smart Documents (Word, Excel) “Disable Smart Document's use of manifests” must be set to “Enabled”.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\Common\Smart Tag

Criteria: If the value NeverLoadManifests is REG_DWORD = 1, this is not a finding.
Fix Text (F-29647r1_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Office 2010 -> Smart Documents (Word, Excel) “Disable Smart Document's use of manifests” to “Enabled”.