• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
microsoft disables internet macros in office apps by default to

Microsoft Disables Internet Macros in Office Apps by Default to Block Malware Attacks

You are here: Home / General Cyber Security News / Microsoft Disables Internet Macros in Office Apps by Default to Block Malware Attacks
February 8, 2022

Microsoft on Monday explained it is having methods to disable Visual Fundamental for Applications (VBA) macros by default across its products and solutions, which includes Term, Excel, PowerPoint, Access, and Visio, for documents downloaded from the web in an endeavor to eradicate an whole class of attack vector.

“Undesirable actors ship macros in Workplace data files to stop consumers who unknowingly allow them, destructive payloads are delivered, and the effects can be intense such as malware, compromised identity, facts reduction, and remote access,” Kellie Eickmeyer said in a post announcing the shift.

Automatic GitHub Backups

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


When the organization does alert users about allowing macros in Office environment files, unsuspecting consumers — e.g., recipients of phishing e-mail — can still be lured into enabling the element, correctly granting the attackers the capacity to get an first foothold into the process.

As element of the new transform, when a consumer opens an attachment or downloads from the internet an untrusted Office environment file that contains macros, the application shows a security risk banner stating, “Microsoft has blocked macros from working for the reason that the supply of the file is untrusted.”

Microsoft Blocks Internet VBA Macros

“If a downloaded file from the internet wishes you to enable macros, and you happen to be not specified what those people macros do, you should really most likely just delete that file,” Microsoft cautions, outlining the security risk of poor actors employing macros.

Prevent Data Breaches

That stated, people can unblock macros for any downloaded file by suitable-clicking the file and deciding upon Homes from the context menu, and ticking the “Unblock” checkbox from the Basic tab. The updates are predicted to be used to Microsoft 365 end users in April 2022, with plans to backport the element to Office environment LTSC, Place of work 2021, Business office 2019, Office 2016, and Place of work 2013 at a “long run date.”

The shift arrives much less than a month soon after the Windows maker disabled Excel 4. (XLM) macros, yet another extensively abused function to distribute malware, by default for shielding clients versus security threats.

Identified this post attention-grabbing? Stick to THN on Fb, Twitter  and LinkedIn to study much more exceptional information we publish.


Some pieces of this write-up are sourced from:
thehackernews.com

Previous Post: «microsoft temporarily disables msix app installers to prevent malware abuse Microsoft Temporarily Disables MSIX App Installers to Prevent Malware Abuse
Next Post: How Attack Surface Management Preempts Cyberattacks how attack surface management preempts cyberattacks»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.