Check: DTOO154 - Word
Microsoft Word 2007:
DTOO154 - Word
(in versions v4 r15 through v4 r14)
Title
Block Opening of "Open XML" file types to prevent them automatically executing code. (Cat II impact)
Discussion
The Office Open XML format file types introduced in the 2007 Microsoft Office release offer a number of benefits compared to the previous binary file types supported in Office 2003, including the potential to reduce the effects of malicious code. Files can be identified as unable to run code, and will therefore ignore any embedded code. Also, any files that do have embedded code are easier to identify. If a vulnerability is discovered that affects Office Open XML files, you can use this setting to protect your organization against attacks by temporarily preventing users from opening files in these formats until a security patch is available.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Word 2007 -> Block file formats -> Open “Block opening of Open XML file types” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock Criteria: If the value OpenXmlFiles is REG_DWORD = 0, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Word 2007 -> Block file formats -> Open “Block opening of Open XML file types” will be set to “Disabled”.
Additional Identifiers
Rule ID: SV-18593r1_rule
Vulnerability ID: V-17519
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |