2.2.4.7.2.2.14 (L1) Ensure 'Web pages and Excel 2003 XML spreadsheets' is set to 'Enabled: Open/Save blocked, use open policy'

Information

This policy setting determines whether users can open, view, edit, or save Web pages and Excel 2003 XML spreadsheets.

Open/Save blocked, use open policy : Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the 'default file block behavior' key.

Note:

Use Open Policy

action is defined by the

Set default file block behavior

policy setting which is included in this benchmark.

The recommended state for this setting is: Enabled: Open/Save blocked, use open policy

Using legacy file formats could allow malicious code to become active on a user's computer or the network.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Open/Save blocked, use open policy

Microsoft Excel 2016\Excel Options\Security\Trust Center\File Block Settings\Web Pages and Excel 2003 XML Spreadsheets

Impact:

Users will not be able to open, save, or view Web pages and Excel 2003 XML spreadsheets. In addition, the following file types will open in Protected View:mht mhtml htm html xml xlmss

While in OneNote using the function 'Convert a Table to Excel' may cause OneNote to freeze until a dialogue box is confirmed.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.2.

Plugin: Windows

Control ID: b158f8c0e18a51ab05b067574520d1d2632d50e1f0b465303ab3719a50b3905c