The "file formats new to Word, Excel, and Powerpoint 2007" refer to the 128 bit AES encryption and SHA-1 hashing used by Office 2007. ![]() "By installing the Compatibility Pack in addition to Microsoft Office 2000, Office XP, or Office 2003, you will be able to open, edit, and save files using the file formats new to Word, Excel, and PowerPoint 2007." This weakness is addressed by installing the Microsoft Office Compatability pack: This meant that if an attacker observed multiple copies of a document (say as people e-mailed it back and forth with tracked changes) then the attacker could crack the password by comparing the various versions of the document. Originally in Office 2003, the encryption improperly used the RC4 stream cipher ( The Misuse of RC4 in Microsoft Word and Excel) with a 128-bit key with a common initialization vector and key stream for a document regardless of how many times it was encrypted.
0 Comments
Leave a Reply. |