1.4.7.2.1.7 Ensure 'dBase III /IV Files' is set to Enable (Open/Save blocked, use open policy)

Information

This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting. The recommended state for this setting is: Enabled. (Open/Save blocked, use open policy) By default, users can open dBase III / IV files in Excel. If a vulnerability is discovered that affects these file types, you can use this setting to protect your organization against attacks by temporarily preventing users from opening files in these formats until a security update is available.

Solution

To implement the recommended configuration state, set the following Group Policy setting to Enabled. User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Trust Center\File Block Settings\dBase III /IV Files Impact: If your users must work with business-critical files that include these file types, enabling this setting could cause significant disruptions. Users who do not work with dBase III / IV files will likely not be affected by this setting.

See Also

https://workbench.cisecurity.org/files/569

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.2.

Plugin: Windows

Control ID: cf023d474f440ebd568a856ecb55f4e9e8d6b93074d23b2ae66276acd198c770