2.2.4.7.4 (L1) Ensure 'Scan encrypted macros in Excel Open XML workbooks' is set to 'Enabled: Scan encrypted macros (default)'

Information

This policy setting controls whether encrypted macros in Open XML documents are required to be scanned with anti-virus software before being opened.

The recommended state for this setting is: Enabled: Scan encrypted macros (default)

When an Office Open XML document is rights-managed or password protected, macros that are embedded in the document are encrypted along with the rest of the workbook's contents. Macros can contain malicious code which could cause a virus to load undetected and lead to data loss or reduced application functionality.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Scan encrypted macros (default)

Microsoft Excel 2016\Excel Options\Security\Scan Encrypted Macros in Excel Open XML Workbooks

Impact:

None - this is the default behavior.

By default, encrypted macros will be disabled unless they are scanned by antivirus software immediately before being loaded.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3

Plugin: Windows

Control ID: 325f6eb39afa6538c3fbfb56f84d127c03ac584cfe247c4c9f8445d3f08407a6