OFFICE By Mary Branscombe Inside every Office file is a hierarchy of formats and XML markup. If you understand these structures, you can use that know
[See the full post at: Understanding Office document formats]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Understanding Office document formats
Home » Forums » Newsletter and Homepage topics » Understanding Office document formats
- This topic has 10 replies, 6 voices, and was last updated 7 months ago.
AuthorTopicMary Branscombe
AskWoody MVPApril 29, 2024 at 2:44 am #2665257Viewing 5 reply threadsAuthorReplies-
MikeLainhart
AskWoody Plus -
Mary Branscombe
AskWoody MVP
-
bbotz
AskWoody PlusApril 29, 2024 at 1:24 pm #2665435I knew how to get to the zip format for Excel, but never looked for the other formats. I must say you did a great job explaining the file storage structure. Thanks!!!
1 user thanked author for this post.
RetiredGeek
AskWoody_MVPApril 29, 2024 at 1:39 pm #2665437Mary,
Great article! This is very useful information.
RG
1 user thanked author for this post.
TechTango
AskWoody PlusApril 29, 2024 at 10:28 pm #2665571Mary, thank you for all the handy information. This leads me to a question:
I’m an Office 365 subscriber and occasionally will password protect Word docx files which also encrypts them with SHA-256 military encryption. It certainly passes the HEX editor test, but as complex as MS Word has become I sometimes wonder if this can create vulnerabilities in the SHA-256 structure.
What is your take on this?
Desktop mobo Asus TUF X299 Mark 1, CPU: Intel Core i7-7820X Skylake-X 8-Core 3.6 GHz, RAM: 32GB, GPU: Nvidia GTX 1050 Ti 4GB. Display: Four 27" 1080p screens 2 over 2 quad.-
Mary Branscombe
AskWoody MVPMay 16, 2024 at 1:45 pm #2672143TechTango, the complexity of what you’re encrypting doesn’t affect the protection you get from an encryption scheme. Although there’s the possibility of collisions with SHA-256, the numbers involved are astronomically large and the amount of computation required is currently unfeasible assuming the cryptography has been implemented well (and as Mike points out, Microsoft’s implementation has been audited and widely tested). Although there are tools that can crack password hashes, they work best if people have used weak passwords so you can protect yourself by making sure you pick a strong one. In fact, the fact that Microsoft had to make a tool called DocRecrypt for IT admins to switch Office document encryption to be managed by certificates that allow the IT team to unlock documents when people forget their password suggests that the password protection is pretty secure. The main threat is people guessing your password, so again, make sure it’s a good one!
Mike
GuestMay 2, 2024 at 8:36 am #2666589IIRC, Microsoft began using the OPC (Open Packaging Conventions) containers to store office files circa ~2006/2007? I think it debuted publicly in Office 2007.
@TechTango AES256 (vs SHA256) would be used for the encryption. I have never personally validated it’s implementation as used for Office files, but I recall writing decryptors for such files in the past and the data successfully decrypted.Encryption done correctly (initialization vectors, random padding, feedback, etc.) theoretically mitigates many of the publicly known vulnerabilities. It’s highly likely many have analyzed MSFT’s implementation to confirm it was done correctly. That doesn’t stop MSFT from screwing the code up again later. A larger threat is the push to move to ECC, FIDO/2 and other “just trust us, we deleted the seed values so it’s secure” crypto systems.
My advice: For anything that must be kept absolutely secure– don’t store it on a computer. If you must store it on a computer, don’t interface with it using Windows.
Good luck!
-
Mary Branscombe
AskWoody MVPMay 16, 2024 at 1:50 pm #2672148yes, Office Open XML has been around for a while: Office 2000 and 2003 let you create documents programmatically using .NET and XML but the new file format came in with Office 2007 and then got standardised through ECMA. But it turned out we’d never written up how you could use it for more than just saving files!
TechTango
AskWoody PlusMay 16, 2024 at 8:57 pm #2672273The main threat is people guessing your password, so again, make sure it’s a good one!
Thank for your detailed response. VERY helpful, and yes, my PW is a super solid assortment of numbers, characters, upper & lower letters. 20 of them = brute force over 19qn years.
Desktop mobo Asus TUF X299 Mark 1, CPU: Intel Core i7-7820X Skylake-X 8-Core 3.6 GHz, RAM: 32GB, GPU: Nvidia GTX 1050 Ti 4GB. Display: Four 27" 1080p screens 2 over 2 quad.-
Mary Branscombe
AskWoody MVPOctober 18, 2024 at 11:08 am #2711183returning to this to note that NIST guidance on secure passwords is changing from the hard to remember mix of special characters and cases to longer strings made up of a multiword phrase; PickAMemorablePhrase (or the classic BatteryHorseStaple) should be easier to remember but just as hard to crack. Making security simple enough for people to use properly improves security.
1 user thanked author for this post.
Viewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Fixing Windows 24H2 failed KB5058411 install
by
Alex5723
1 hour, 51 minutes ago -
Out of band for Windows 10
by
Susan Bradley
3 hours, 24 minutes ago -
Giving UniGetUi a test run.
by
RetiredGeek
10 hours, 21 minutes ago -
Windows 11 Insider Preview Build 26100.4188 (24H2) released to Release Preview
by
joep517
17 hours, 58 minutes ago -
Microsoft is now putting quantum encryption in Windows builds
by
Alex5723
15 hours, 57 minutes ago -
Auto Time Zone Adjustment
by
wadeer
22 hours, 28 minutes ago -
To download Win 11 Pro 23H2 ISO.
by
Eddieloh
20 hours, 8 minutes ago -
Manage your browsing experience with Edge
by
Mary Branscombe
43 minutes ago -
Fewer vulnerabilities, larger updates
by
Susan Bradley
11 hours, 39 minutes ago -
Hobbies — There’s free software for that!
by
Deanna McElveen
15 hours, 56 minutes ago -
Apps included with macOS
by
Will Fastie
15 hours, 34 minutes ago -
Xfinity home internet
by
MrJimPhelps
15 hours, 29 minutes ago -
Convert PowerPoint presentation to Impress
by
RetiredGeek
15 hours, 27 minutes ago -
Debian 12.11 released
by
Alex5723
1 day, 19 hours ago -
Microsoft: Troubleshoot problems updating Windows
by
Alex5723
1 day, 23 hours ago -
Woman Files for Divorce After ChatGPT “Reads” Husband’s Coffee Cup
by
Alex5723
1 day, 2 hours ago -
Moving fwd, Win 11 Pro,, which is best? Lenovo refurb
by
Deo
19 hours, 8 minutes ago -
DBOS Advanced Network Analysis
by
Kathy Stevens
2 days, 16 hours ago -
Microsoft Edge Launching Automatically?
by
healeyinpa
2 days, 6 hours ago -
Google Chrome to block admin-level browser launches for better security
by
Alex5723
4 hours, 20 minutes ago -
iPhone SE2 Stolen Device Protection
by
Rick Corbett
2 days, 11 hours ago -
Some advice for managing my wireless internet gateway
by
LHiggins
1 day, 18 hours ago -
NO POWER IN KEYBOARD OR MOUSE
by
HE48AEEXX77WEN4Edbtm
20 hours, 39 minutes ago -
A CVE-MITRE-CISA-CNA Extravaganza
by
Nibbled To Death By Ducks
3 days, 4 hours ago -
Sometimes I wonder about these bots
by
Susan Bradley
16 hours, 28 minutes ago -
Does windows update component store “self heal”?
by
Mike Cross
2 days, 14 hours ago -
Windows 11 Insider Preview build 27858 released to Canary
by
joep517
3 days, 18 hours ago -
Pwn2Own Berlin 2025: Day One Results
by
Alex5723
2 days, 2 hours ago -
Windows 10 might repeatedly display the BitLocker recovery screen at startup
by
Susan Bradley
1 day, 14 hours ago -
Windows 11 Insider Preview Build 22631.5409 (23H2) released to Release Preview
by
joep517
3 days, 21 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.