Word 2010: Save as PDF causes XXE problems

My company has been experiencing problems with Word documents saved as PDFs.  The process appears to inject external XML Entities (XXE) into the document that make our firewall flag them as threats.  

It appears to be only from documents saved as PDF using an Office application's Save As dialog.

For the time being, I've told my users to stop making PDFs this way, and instead print through the PDF printer that came with Adobe Acrobat Pro.  None of those PDFs cause the problem.

But it's often difficult to get users to do something if it's more complicated, and the complaint usually comes from a website editor who is blocked from uploading the PDF, far down the chain from the person who created the PDF.  Sometimes the creator is from a different organization.

I'm not interested in discussing firewall configuration in a group dedicated to Office, but I would like to know what it is about Office's save as PDF that puts this unneccessary stuff in the resulting PDFs. 


  • Edited by Spencer Simpson Friday, May 08, 2015 1:57 PM clean up unnecessary paste
May 8th, 2015 1:57pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics