Check: DTOO150 - Excel
Microsoft Excel 2010:
DTOO150 - Excel
(in versions v1 r11 through v1 r10)
Title
Update of automatic links must be configured to prompt. (Cat II impact)
Discussion
If an Excel workbook contains links to other documents and users are not prompted to approve them, the contents of the workbook might change without the users' knowledge because the linked files have changed. By default, users are prompted to update automatic links.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Advanced “Ask to update automatic links” must be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\excel\options\binaryoptions Criteria: If the value fUpdateExt_78_1 is REG_DWORD = 0, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Advanced “Ask to update automatic links” to “Enabled”.
Additional Identifiers
Rule ID: SV-33434r1_rule
Vulnerability ID: V-17732
Group Title: DTOO150 - Automatic Link Updates
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001243 |
The organization configures malicious code protection mechanisms to perform organization-defined action(s) in response to malicious code detection. |
Controls
Number | Title |
---|---|
SI-3 |
Malicious Code Protection |