2.3.27.6 (L1) Ensure 'Allow VBA to load typelib references by path from untrusted intranet locations' is set to 'Disabled'

Information

This policy setting permits VBA to load typelib references by explicit path read from the project data if that path points to an intranet location that is not explicitly in the system trusted sites list.

If this policy setting is enabled, VBA will treat intranet paths like local machine paths, and therefore VBA will attempt to search for unregistered references in intranet locations that are not local machine or in the system's trusted sites list.

The recommended state for this setting is: Disabled

The Visual Basic Application language can be abused by manipulating typelib references stored in untrusted locations. By preventing a user from overriding the default security settings this prevents a change to an unsecure state where harmful software could be more easily executed on a system.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Office 2016\Security Settings\Allow VBA to load typelib references by path from untrusted intranet locations

Impact:

None - this policy enforces the default configuration.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, 800-53|CM-7(1)

Plugin: Windows

Control ID: 661851dd3f63de37bd7564b23486d5ec58dcd0eb58b459f26248c82bb9898a68