Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-17563 | DTOO299 - PowerPoint | SV-18665r1_rule | ECSC-1 | Medium |
Description |
---|
PowerPoint 2007 requires the use of a conversion tool to open presentations saved in versions of PowerPoint older than PowerPoint 97, such as PowerPoint 95, PowerPoint 4.0, and others. If a vulnerability is discovered that affects these kinds of files, you can use this setting to protect your organization against attacks by temporarily preventing users from opening files in these formats until a security patch is available. |
STIG | Date |
---|---|
Microsoft PowerPoint 2007 | 2014-01-07 |
Check Text ( C-18864r1_chk ) |
---|
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Open “Block opening of Converters” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock Criteria: If the value Converters is REG_DWORD = 1, this is not a finding. |
Fix Text (F-17480r1_fix) |
---|
The policy value for User Configuration -> Administrative Templates -> Microsoft Office PowerPoint 2007 -> Block file formats -> Open “Block opening of Converters” will be set to “Enabled”. |