Policies to disable browsing 'my computer' don't prevent users from doing the same thing in Word and Excel
Posted on 2006-07-14
On a W2K3 Terminal Server with many policies I found a very stupid securty leak. With the policies I've disallowed users to browse 'my computer'. They cannot go to c:\ or d:\ from the explorer address bar.
But when a user starts MS Office Word (or any other office application) it's possible to click 'my computer' from the 'file/open' menu. Also it's possible to browse to c:\ and d:\ from the file location bar.
Is there a way to make office applications more secure? To disable those features?