DTOO119 - Configuration for file validation must be enforced.

Information

Office File Validation helps detect and prevent a kind of exploit known as a file format attack or file fuzzing attack. File format attacks exploit the integrity of a file. They occur when someone modifies the structure of a file with the intent of adding malicious code. Usually the malicious code is run remotely and is used to elevate the privilege of restricted accounts on the computer. As a result, an attacker could gain access to a computer that they did not previously have access to. This could enable an attacker to read sensitive information from the computer's hard disk drive or install malware, such as a worm or a key logging program. The Office File Validation feature helps prevent file format attacks by scanning and validating files before they are opened. To validate files, Office File Validation compares a file's structure to a predefined file schema, which is a set of rules that determine what a readable file looks like. If Office File Validation detects that a file's structure does not follow all rules that are described in the schema, the file does not pass validation.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Word 2013 -> Word Options -> Security 'Turn off file validation' to 'Disabled'.

See Also

http://iasecontent.disa.mil/stigs/zip/U_MicrosoftWord2013_V1R5_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-53559r1_rule, STIG-ID|DTOO119, Vuln-ID|V-26592

Plugin: Windows

Control ID: 01072a46acd665dc99464c05cef6c4dcbb83694ffc923f8b922334effab12133