File types must be configured to provide mismatch warnings.

From Microsoft Excel 2010

Part of DTOO143 - Force File Extension to match type

Associated with: CCI-001243

SV-33440r1_rule File types must be configured to provide mismatch warnings.

Vulnerability discussion

Excel can load files with extensions that do not match the files' type. For example, if a comma-separated values (CSV) file named example.csv is renamed example.xls, Excel can properly load it as a CSV file.Some attacks target specific file formats. If Excel is allowed to load files with extensions that do not match their file types, a malicious person can deceive users into loading dangerous files that have incorrect extensions.By default, if users attempt to open files with the wrong extension, Excel opens the file and displays a warning that the file type is not what Excel expected.

Check content

The policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Security “Force file extension to match file type” must be set to “Enabled (Allow different, but warn)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\excel\security Criteria: If the value ExtensionHardening is REG_DWORD = 1, this is not a finding.

Fix text

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Security “Force file extension to match file type” to “Enabled (Allow different, but warn)”.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer