2.2.4.7.6 (L1) Ensure 'WEBSERVICE Function Notification Settings' is set to 'Enabled: Disable all without notification'

Information

This policy setting controls how Excel will warn users when WEBSERVICE functions are present.

When selecting the option 'Disable all with notification' the application displays the Trust Bar for all WEBSERVICE functions. This option enforces the default configuration in Office.

The recommended state for this setting is: Enabled: Disable all without notification or Enabled: Disable all with notification

WEBSERVICE functions can be used alongside formula injection to cause users of an Excel spreadsheet to unknowingly connect to systems controlled by bad actors, or even exfiltrate data.

Solution

To establish the recommended state via configuration profiles, set the following Settings Catalog path to Enabled: Disable all without notification or Enabled: Disable all with notification

Microsoft Excel 2016\Excel Options\Security\WEBSERVICE Function Notification Settings

Impact:

Users will not be notified when a WEBSERVICE function is disabled.

See Also

https://workbench.cisecurity.org/benchmarks/15808

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 0677983a6df5c19af7fc00ff69439d8fc5b8f815f070fb1ca1bb1e92ba7629d3