2.2.4.7.2.10 Ensure 'Prevent Excel from running XLM macros' is set to 'Enabled'

Information

This policy setting will prevent Excel from running Excel 4.0 (XLM) macros. XLM macros were first added to Excel in 1992, and were disabled in Excel (Build 16.0.14427.10000) by Microsoft in 2021.

The recommended state for this setting is: Enabled.

Rationale:

XLM is data macro format from the early nineties that was not built with security in mind. Macros can be easily exploited and are a favorite hiding place of malicious code. While newer builds of Excel disable XLM macros by default, it is an important setting to audit for a secure state in all versions of Excel.

Impact:

This enforces the default behavior. Existing XLM macros will not function, and should be migrated.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled.

User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Trust Center\Prevent Excel from running XLM macros

Default Value:

Enabled. (XLM Macros are blocked)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1)

Plugin: Windows

Control ID: f79ce1f0df8fdc0c9280a97e58fb78426cc7438daa356a1e4e1484c179492816