DTOO154 - Excel - Block Opening of 'Open XML' file types to prevent them automatically executing code.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Office Open XML format file types introduced in the 2007 Microsoft Office release offer a number of benefits compared to the previous binary file types supported in Office 2003, including the potential to reduce the effects of malicious code. Files can be identified as unable to run code, and will therefore ignore any embedded code. Also, any files that do have embedded code are easier to identify.
If a vulnerability is discovered that affects Office Open XML files, you can use this setting to protect your organization against attacks by temporarily preventing users from opening files in these formats until a security patch is available.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office Excel 2007 -> Block file formats -> Open 'Block opening of Open XML file types' will be set to 'Disabled'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

References: CAT|II, Rule-ID|SV-18595r2_rule, STIG-ID|DTOO154, Vuln-ID|V-17519

Plugin: Windows

Control ID: 145541d75e21da436302c2b2068df82fcdda0df8dfc957c88a544990af05202e