There has been some back and forth since the change was originally announced, but this week Microsoft began rolling out an update to Microsoft Office that blocks the use of Visual Basic for Applications (VBA) macros in downloaded documents.
Last month, Microsoft was testing the new default setting when it suddenly canceled the update “temporarily until we make some additional changes to improve usability.” Although they said it was temporary, many experts worried that Microsoft might not go through with changing the default setting, leaving systems vulnerable to attacks. Google Threat Analysis Group head Shane Huntley tweeted, “Blocking Office macros would do infinitely more to actually protect against real threats than all the threat blog posts.”
The new default setting is now being introduced, but with updated language to warn users and administrators what options they have when they try to open a file and it’s blocked. This only applies if Windows, using the NTFS file system, marks it as downloaded from the Internet, not a network drive or a site that administrators have marked as safe, and does not change anything on other platforms such as Mac, Office on Android / iOS or Office in the network.
Microsoft:
We resume rolling out this change to the current channel. Based on our review of customer feedback, we’ve made updates to both our end-user documentation and our IT admin documentation to clarify what options you have for different scenarios. For example, what to do if you have files in SharePoint or files on a network share. Please see the following documentation:
• For end users, a potentially dangerous macro is blocked
• For IT administrators, macros from the Internet will be blocked by default in Office
If you have ever enabled or disabled blocking macros in Office files from Internet Policy, your organization will not be affected by this change.
While some people use the scripts to automate tasks, hackers have been abusing the feature with malicious macros for years, tricking people into downloading a file and running it to compromise their systems. Microsoft noted how administrators can use Group Policy settings in Office 2016 to block macros on their organization’s systems. Not everyone turned it on, however, and attacks continued, allowing hackers to steal data or distribute ransomware.
Users who try to open files and are blocked will get a popup that sends them to this page, explaining why they probably don’t need to open that document. It starts by going through a few scenarios where someone might try to trick them into running malware. If they really need to see what’s inside the downloaded file, it explains ways to gain access that are more sophisticated than what happened before, where users could usually activate macros by pressing a button in the warning banner.
This change may not always prevent someone from opening a malicious file, but it provides a few more layers of warning before they can get there, while providing access for people who say they absolutely need it.
Add Comment