Hi,
seeing that even today, people still upload files in the insecure old office formats like DOC and XLS (opposed to the "modern" DOCX and XLSX formats), I would like to suggest to consider banning these old formats.
Here's a quote from a recent article on the topic :
office-watch.com
Of course, I'm confident that the forum members simply share their old files with no malevolent intentions, but as it would be a quick and easy for anyone to re-save a file as DOCX or XLSX before uploading it, I think this might be an opportunity to improve everyone's security with only a minimum of overhead.
The old formats offer functionality that can be abused in ways that even anti-malware software won't protect against. (They're in fact banned in most corporate environments as a SOP.)
Regards,
Henning (HoHun)
seeing that even today, people still upload files in the insecure old office formats like DOC and XLS (opposed to the "modern" DOCX and XLSX formats), I would like to suggest to consider banning these old formats.
Here's a quote from a recent article on the topic :
"The only ‘legitimate’ use of the old formats is to spread viruses, ransomware or steal data. Most viruses using Office documents rely on the older document formats (usually Word .doc) to spread."

Old Office documents should be banned
After our suggestion to ignore old style Office documents, it's clear some folks haven't changed or still accept the older .doc .xls or .ppt files as email atta
Of course, I'm confident that the forum members simply share their old files with no malevolent intentions, but as it would be a quick and easy for anyone to re-save a file as DOCX or XLSX before uploading it, I think this might be an opportunity to improve everyone's security with only a minimum of overhead.
The old formats offer functionality that can be abused in ways that even anti-malware software won't protect against. (They're in fact banned in most corporate environments as a SOP.)
Regards,
Henning (HoHun)