Microsoft Disables Internet Macros in Office Apps by Default to Block Malware Attacks

Microsoft Blocks Internet VBA Macros

Microsoft on Monday said it’s taking steps to disable Visual Basic for Applications (VBA) macros by default across its products, including Word, Excel, PowerPoint, Access, and Visio, for documents downloaded from the web in an attempt to eliminate an entire class of attack vector.

“Bad actors send macros in Office files to end users who unknowingly enable them, malicious payloads are delivered, and the impact can be severe including malware, compromised identity, data loss, and remote access,” Kellie Eickmeyer said in a post announcing the move.

Automatic GitHub Backups

While the company does warn users about permitting macros in Office files, unsuspecting users — e.g., recipients of phishing emails — can still be lured into enabling the feature, effectively granting the attackers the ability to gain an initial foothold into the system.

As part of the new change, when a user opens an attachment or downloads from the internet an untrusted Office file containing macros, the app displays a security risk banner stating, “Microsoft has blocked macros from running because the source of the file is untrusted.”

Microsoft Blocks Internet VBA Macros

“If a downloaded file from the internet wants you to allow macros, and you’re not certain what those macros do, you should probably just delete that file,” Microsoft cautions, outlining the security risk of bad actors using macros.

Prevent Data Breaches

That said, users can unblock macros for any downloaded file by right-clicking the file and selecting Properties from the context menu, and ticking the “Unblock” checkbox from the General tab. The updates are expected to be applied to Microsoft 365 users in April 2022, with plans to backport the feature to Office LTSC, Office 2021, Office 2019, Office 2016, and Office 2013 at a “future date.”

The move arrives less than a month after the Windows maker disabled Excel 4.0 (XLM) macros, another widely abused feature to distribute malware, by default for protecting customers against security threats.

Rodion Krotov
Written by
Rodion Krotov
📧
Stay Ahead of the Market
Get the latest crypto, gambling, and presale news delivered to your inbox weekly.
No spam. Unsubscribe anytime.

Related Articles

Comments

📰 Latest Articles

🔥 Most Read

🎰 Top Casino

Stake ★★★★★ 9.5
Up to $3,000
200% welcome bonus + 50 free spins
No KYC Instant Withdrawals VIP Program
BTC ETH USDT SOL LTC DOGE +4
BC.Game ★★★★★ 9.2
Up to $20,000
300% deposit bonus across 4 deposits
100+ Cryptos Provably Fair Live Casino
BTC ETH USDT SOL DOGE BNB +2
Betway ★★★★★ 8.8
Up to $1,500
100% match bonus + 150 free spins
Licensed UK & Malta Mobile App eCOGRA Certified
BTC ETH Visa Mastercard Apple Pay Skrill +2

🚀 Hot Presale

Patos $PATOS
★★★★☆ 7.8
0.000139999993 Round 1 of 3
$110K+ raised $11M (Liquidity Pool Target)
Ends:
--D
--H
--M
--S
Ethereum Solana
Remittix $RTX
★★★★☆ 8.2
$0.0119 Late Stage (93%+ sold)
$29.7M raised $30M
Ends:
--D
--H
--M
--S
Ethereum Solana
Moonshot MAGAX $MAGAX
★★★★☆ 6.8
$0.000318 Stage 3
$115K+ raised $500K
Ends:
--D
--H
--M
--S
Ethereum