In a bid to increase the security and protect users of Office 2003 and Office 2007, Microsoft is releasing an add-in tool for older versions of Office productivity suite named Office File Validation. Office File Validation is a security add-in for Office 2003 and 2007 that can be used to scan, validate and verify that Binary File Format files conform to the Microsoft Office File Format before they’re opened.

Office files especially unsolicited Word documents, Excel workbooks, and PowerPoint presentations from unknown or known source, which have always been more trusted by end-users, have been the major loophole exploited by malicious hackers to inject malformed data such as malformed data to spread malware.

Office File Validation add-in is already comes as standard built-in in certain edition of Office 2010. According to Microsoft Security Advisor, Office File Validation helps detect and prevent a kind of exploit known as a file format attack. File format attacks exploit the integrity of a file, and occur when the structure of a file is modified with the intent of adding malicious code.

The modified Office flles will fail the file structure validation check against a predefined file schema, which is a set of rules that define what a readable file looks like. When the Office File Validation detects that a file’s structure does not follow all rules described in the schema, the file does not pass validation and could not be opened with the following error message, although the user is provided with choice to open the file anyway.

Office File Validation detected a problem trying to open the file. Opening it may be dangerous.

Office File Validation add-in works when opening an Office file using Microsoft Excel 2003, Microsoft PowerPoint 2003, Microsoft Word 2003, Microsoft Publisher 2003, Microsoft Excel 2007, Microsoft PowerPoint 2007, Microsoft Word 2007, or Microsoft Publisher 2007, and it scans and validates the folloiwing kinds of files:

  • Excel 2.0, Excel 3.0, Excel 4.0, Excel 5.0, Excel 97-2003 Workbook files. These types of files have an .xls extension and include all Binary Interchange File Format 2 (BIFF2), BIFF3, BIFF4, and BIFF8 files.
  • Excel 2.0, Excel 3.0, Excel 4.0, Excel 5.0, Excel 97-2003 Template files. These types of files have an .xlt extension and include BIFF2, BIFF3, BIFF4, and BIFF8 files.
  • PowerPoint 97-2003 Presentation files. These files have a .ppt extension.
  • PowerPoint 97-2003 Show files. These files have a .pps extension.
  • PowerPoint 97-2003 Template files. These files have a .pot extension.
  • Word 6.0, Word 7.0, and Word 97-2003 Document files. These files have a .doc extension.
  • Word 6.0, Word 7.0, and Word 97-2003 Template files. These files have a .dot extension.

Office File Validation add-in is available for free download from Microsoft Download Center, or directly download with the link below. Note that there are several prerequisite architecture updates to Microsoft Word and Microsoft Publisher before you can install Office File Validation as specified in KB2501584, which should have delivered automatically via Microsoft (Windows) Update.

Microsoft Office File Validation Add-in (KB2501584): SFV.exe