2.3.32.1 Ensure 'Disable Smart Document's use of manifests' is set to 'Enabled'

Information

This policy setting controls whether Office applications can load an XML expansion pack manifest file with a Smart Document.

An XML expansion pack is the group of files that constitutes a Smart Document in Excel and Word. Packaging of one or more components provides the logic needed for a Smart Document using an XML expansion pack. These components can include any type of file, including XML schemas, Extensible Stylesheet Language Transforms (XSLTs), dynamic-link libraries (DLLs), and image files, as well as additional XML files, HTML files, Word files, Excel files, and text files.

The key component to building an XML expansion pack is creating an XML expansion pack manifest file. By creating this file, the locations of all files that make up the XML expansion pack is specified, as well as information that instructs Office how to set up the files for Smart Document. The XML expansion pack can also contain information about how to set up some files, such as how to install and register a COM object required by the XML expansion pack.

The recommended state for this setting is: Enabled.

Rationale:

XML expansion packs can be used to initialize and load malicious code, which might affect the stability of a computer and lead to data loss.

Impact:

Enabling this setting prevents users from working with Smart Documents.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Office 2016\Smart Documents (Word, Excel)\Disable Smart Document's Use of Manifests

Default Value:

Disabled. (Office 2016 applications can load an XML expansion pack manifest file with a Smart Document.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3)

Plugin: Windows

Control ID: 5710ec447e63bc211d4049184e71e2b25513e3f959a1628fe6cf38f97dac4293