Check: DTOO290 - PowerPoint
Microsoft PowerPoint 2007:
DTOO290 - PowerPoint
(in versions v4 r16 through v4 r15)
Title
Make hidden markup invisible - PowerPoint (Cat II impact)
Discussion
PowerPoint presentations that are saved in standard or HTML format can contain a flag indicating whether markup (comments or ink annotations) in the presentation should be visible when the presentation is open. By default, PowerPoint 2007 ignores this flag when opening a file, and always displays any markup present in the file. In addition, when saving a file, PowerPoint sets the flag to display markup when the presentation is next opened. If this default configuration is changed, PowerPoint sets the flag according to the state of the Show Markup option on the Review tab of the Ribbon when it saves presentations in standard or HTML format. In addition, PowerPoint enables or disables the Show Markup option according to the way the flag is set when it opens files, which means that a presentation saved with hidden markup is opened with the markup still hidden. If a file is saved with hidden markup, users might inadvertently distribute sensitive comments or information to others via the presentation file.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Make hidden markup visible” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Options Criteria: If the value MarkupOpenSave is REG_DWORD = 1, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> PowerPoint Options -> Security “Make hidden markup visible” will be set to “Enabled”.
Additional Identifiers
Rule ID: SV-18943r1_rule
Vulnerability ID: V-17752
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |