Created on
10-28-2024
09:32 AM
Edited on
01-03-2025
03:04 AM
By
Jean-Philippe_P
Description | This article describes that the FortiGate DLP UTM profile is triggered by unexpected file type signatures while scanning Microsoft Office files. |
Scope | FortiGate. |
Solution |
Microsoft Office files (i.e. *.docx, *.xlsx, *.pptx) are .zip archives. The archive contains multiple folders and files (for instance *.xml, *.jpeg file types). This can be verified by opening a Microsoft Office file with an archive application. The following is an example of an unzipped .docx file:
FortiGate will extract the contents of the Microsoft Office file archive and inspect all folders and files. Consequently, a Microsoft Office file can trigger a DLP signature (for example, *.xml) other than the Microsoft Office file extension (for example, *.docx), since a *.docx archive file can contain *.xml files. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.