> Preventing a process from deciding itself which files to access disables so many attack vectors.
It also disables a lot of existing use cases and file types (basically any multi-file file format):
Multi-part archives, multi-part video files, playlists, videos with separate subtitle files, HTML documents containing links to other local HTML documents or referencing various sub-resources (images/videos/audio/style sheets/scripts/...), Audacity projects, images with metadata in external sidecar files, ditto for georeferenced images, QGIS projects, AutoCAD's lock file implementation, DWG files as such, …
Edit: And since we're talking about Office software: Spreadsheets referencing data from other spreadsheets stored in separate files…