Check: DTOO152 - Excel
Microsoft Excel 2010:
DTOO152 - Excel
(in versions v1 r11 through v1 r10)
Title
Load pictures from Web pages must be disallowed. (Cat II impact)
Discussion
When users open Web pages in Excel, Excel loads any graphics included in the pages, regardless of whether they were originally created in Excel. Allowing Excel to load graphics created in other programs can make Excel vulnerable to possible future zero-day attacks using graphic files as an attack vector. If such an event occurs, this setting can be used to mitigate the vulnerability.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Advanced -> Web Options -> General “Load pictures from Web pages not created in Excel” must be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\excel\internet Criteria: If the value DoNotLoadPictures is REG_DWORD = 1, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Advanced -> Web Options -> General “Load pictures from Web pages not created in Excel” to “Disabled”.
Additional Identifiers
Rule ID: SV-33435r1_rule
Vulnerability ID: V-17751
Group Title: DTOO152 - Load pics from Web not in Excel
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001170 |
The information system prevents the automatic execution of mobile code in organization-defined software applications. |
Controls
Number | Title |
---|---|
SC-18 (4) |
Prevent Automatic Execution |