2.6.6.6.5 (L1) Ensure 'Scan encrypted macros in PowerPoint Open XML presentations' is set to 'Enabled: Scan encrypted macros'

Information

This policy setting controls whether encrypted macros in Open XML documents are required to be scanned with antivirus software before being opened.

The recommended state for this setting is: Enabled: Scan encrypted macros

When an Office Open XML document is rights-managed or password protected, macros that are embedded in the document are encrypted along with the rest of the workbook's contents. Macros can contain malicious code which could cause a virus to load undetected and lead to data loss or reduced application functionality.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Scan encrypted macros

Microsoft PowerPoint 2016\PowerPoint Options\Security\Scan encrypted macros in PowerPoint Open XML presentations

Impact:

None - this is the default behavior.

By default, encrypted macros will be disabled unless they are scanned by antivirus software immediately before being loaded.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3

Plugin: Windows

Control ID: b08c2a89f094b2c632c78469e52e0e9ce6cc8166cc4587db3d191326b121e4a0