DTOO143 - Excel - File types must be configured to provide mismatch warnings.

Information

Excel can load files with extensions that do not match the files' type. For example, if a comma-separated values (CSV) file named example.csv is renamed example.xls, Excel can properly load it as a CSV file.
Some attacks target specific file formats. If Excel is allowed to load files with extensions that do not match their file types, a malicious person can deceive users into loading dangerous files that have incorrect extensions.
By default, if users attempt to open files with the wrong extension, Excel opens the file and displays a warning that the file type is not what Excel expected.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Security 'Force file extension to match file type' to 'Enabled (Allow different, but warn)'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Excel_2010_V1R11_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.2., CAT|II, CCI|CCI-001243, Rule-ID|SV-33440r1_rule, STIG-ID|DTOO143, Vuln-ID|V-17621

Plugin: Windows

Control ID: d6254a383fc5306b9b53debbbefbf093a0d709ce5536c814fcccf1e68c2d2847