Microsoft Office 2000 Executable Content Security Risks and Countermeasures
Total Page:16
File Type:pdf, Size:1020Kb
UNCLASSIFIED Report # C4 -07R -02 Date 02/08/2002 Microsoft Office 2000 Executable Content Security Risks and Countermeasures Executable Content Technology Team Systems and Network Attack Center (SNAC) Information Assurance Directorate Sheila Christman Mary Kolencik Released by Curt Dukes Trent Pitsenberger Chief, C43 Linda Smith Brett Sovereign National Security Ag ency ATTN: C43 9800 Savage Rd. STE 6704 (410) 854 -6191 commercial (410) 854 -6510 facsimile Ft. Meade, MD 20755 -6704 UNCLASSIFIED UNCLASSIFIED Microsoft Office 2000 Executable Content Security Risks and Countermeasures Prepared by: Brett Sovereign, C43 Released by: Curtis Dukes Chief, C43 Distribution: 1 - C 14 - DC324 Library No. S -248,496 2 - C Ch Sci 15 - V 3 - C Library 16 - V TD 4 - C1 17 - V2 5 - C11 18 - V3 6 - C12 19 - V4 7 - C3 20 - V5 8 - C4 21 - Vital Records 9 - C4 TD 22 - X 10 - C 41 23 - X TD 11 - C42 24 - X6 12 - C43 25 - X7 13 - C44 26 - X8 UNCLASS IFIED UNCLASSIFIED Abstract This paper provides an overview of the security threats from embedded scripts and binary executables in Office 2000 documents. It recommends ways to mitigate or counter these threats. The four applications covered in this paper are: Microsoft Word - the word processing application Microsoft Excel - the spreadsheet application Microsoft PowerPoint - the presentation application Microsoft Outlook - the mail/groupware application Microsoft Office 2000 includes a number of improvements to security compared to Office 97 as well as some new security features. This document describes these improvements and features, and suggests how best to configure and use the security in Office 2000 to prevent most executable content attacks. Acknowledgements The authors would like to thank Neal Ziring and Ken Katano, for reviewing and providing comments to the original drafts of this paper. UNCLASS IFIED UNCLASSIFIED Table of Contents 1 Introduction ................................ ................................ ................................ ............................. 1 2 Definitions and Background ................................ ................................ ................................ ... 1 2.1 Executable Content and Mobi le Code ................................ ................................ ............ 1 2.2 Customizations of Office Applications ................................ ................................ ........... 2 2.3 Threat and Countermeasure ................................ ................................ ............................ 3 3 Common Office 2000 Security Features ................................ ................................ ................. 3 3.1 Background: Security in Office 97 ................................ ................................ ................. 3 3.2 Security in Office 2000 Word, Excel, and PowerPoint ................................ .................. 4 3.3 Hot Fixes, Patches, and Updates ................................ ................................ ..................... 9 4 Microsoft Word ................................ ................................ ................................ ....................... 9 4.1 Overview ................................ ................................ ................................ ....................... 10 4.2 Threat Potential ................................ ................................ ................................ ............. 11 4.3 Countermeasures for Word ................................ ................................ ........................... 14 4.4 Summary ................................ ................................ ................................ ....................... 15 5 Microsoft Excel ................................ ................................ ................................ ..................... 15 5.1 Overview ................................ ................................ ................................ ....................... 15 5.2 Threats And Vulnerabilities ................................ ................................ .......................... 16 5.3 Countermeasures for Excel ................................ ................................ ........................... 18 5.4 Summary ................................ ................................ ................................ ....................... 18 6 Microsoft PowerPoint ................................ ................................ ................................ ........... 19 6.1 Overview ................................ ................................ ................................ ....................... 19 6.2 Threat Potential ................................ ................................ ................................ ............. 19 6.3 Countermeasures for PowerPoint ................................ ................................ ................. 20 6.4 Summary ................................ ................................ ................................ ....................... 21 7 Microsoft Outlook ................................ ................................ ................................ ................. 21 7.1 Overview ................................ ................................ ................................ ....................... 21 7.2 Threa t Potential ................................ ................................ ................................ ............. 22 7.3 Configuration Recommendations ................................ ................................ ................. 24 7.4 Summary ................................ ................................ ................................ ....................... 29 8 Summary of Op timum Settings and Countermeasures ................................ ......................... 29 9 Conclusions ................................ ................................ ................................ ........................... 30 10 References and Resources ................................ ................................ ................................ 31 Appendix A Registry Settings for Office 2000 ................................ ................................ ............. 32 Appendix B Level 1 Attachments for Outlook Attachment Security Patch ................................ 34 UNCLASSIFIED UNCLASSIFIED 1 Introduction In late 1999, the NSA published a report describing a security analysis of Microsoft Office 97, which is available at http://www.nsa.gov [1]. This paper is an update covering Microsoft Office 2000 SR 1a running on Windows NT with SP4 or later, or Windows 2000. The four components covered in this paper are Microsoft Word – the word processing application Microsoft Excel – the spreadsheet application Microsoft PowerPoint – the presentation application Microsoft Outlook – the mail/groupware application Microsoft Office 2000 includes a number of improvements to security as well as some new security features. This document describes these improvements and features, and suggests how best to configure and use the security in Office 2000 to prevent most executable content attacks. 2 Definitions and Background 2.1 Executable Content and Mobile Code In general terms, an executable content format is one that supports initiation of execution as a side effect of manipulating or viewing the data or its presentation. Mobile code refers to data that is obtained from remote systems, transferred across a network, and then downloaded and executed on a local system without explicit installation or initiation of execution by the recipient. By this definition, not all mobile code is executable content, but most executable content threats utilize mobile code delivery systems such as e-mail and web pages to spread. Microsoft Office 95, 97, and 2000 include the Visual Basic for Applications (VBA) language in Word, Excel and PowerPoint.1 VBA is derived from Visual Basic and is an interpreted extension language to allow a user to customize the individual Microsoft Office applications. Microsoft licenses VBA to other software vendors to include in their products, and the security concerns are similar. Since the implementation of VBA allows a data format (e.g. Word document) to include code that executes automatically without initiation by the user (e.g. an AutoOpen macro), VBA is executable content. VBA enabled formats also fit the definition of mobile code since documents, spreadsheets, and presentations can be sent over a network as e-mail attachments or can be opened in Internet Explorer (a web browser). For simplicity, this paper will use the term executable content rather than mobile code. 1 Access and Frontpage also include VBA, but those products will not be covered in this paper since their security features and settings are different from the other main components of Office 2000. Prior to Office 95, only Microsoft Word 6.0 included an extension language, and that was WordBasic. The Office 95 implementation of VBA and Word 6.0’s WordBasic will not be covered in any detail in this paper. 1 UNCLASSIFIED UNCLASSIFIED 2.2 Customizations of Office Applications 2.2.1 The purpose of VBA Macros and ActiveX The Microsoft Office applications have extensive built-in functionality. However, there are times when a user may want to customize or add to that functionality. For example, in Word there is no built-in button to print just the current page. The user has to select the File menu, select Print, select Current Page, and select Okay – four mouse clicks. A button on the