Open/Save actions for dBase III / IV files must be blocked.

From Microsoft Excel 2010

Part of DTOO122 - dBase III / IV files

SV-34230r1_rule Open/Save actions for dBase III / IV files must be blocked.

Vulnerability discussion

This policy setting allows for determining whether users can open, view, edit, or save Excel files with the format specified by the title.

Check content

The policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Security -> Trust Center -> File Block Settings “dBase III / IV files” must be “Enabled: Open/Save blocked, use open policy". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\excel\security\fileblock Criteria: If the value DBaseFiles is REG_DWORD = 2, this is not a finding.

Fix text

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Security -> Trust Center -> File Block Settings “dBase III / IV files” to “Enabled: Open/Save blocked, use open policy".

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer