Information
This rule prevents VBA macros from calling Win32 APIs. Office VBA enables Win32 API calls.
The recommended state for this setting is: Block
Malware can abuse VBA macro calls with various methods, such as calling Win32 APIs to launch malicious shellcode without writing anything directly to disk. Most organizations don't rely on the ability to call Win32 APIs in their day-to-day functioning, even if they use macros in other ways.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Block
Defender\Block Win32 API calls from Office macros
Impact:
Files copied from the USB to the disk drive will be blocked by this rule if and when it's about to be executed on the disk drive.