2.2.4.7.2.5 Ensure 'Block Excel XLL Add-ins that come from an untrusted source' is set to 'Enabled: Blocked'

Information

An Excel add-in is a collection of custom code and functionality that enhances Microsoft Excel's capabilities. These add-ins can be created by third-party developers or by Excel users themselves. Once installed, they become part of Excel and can be used across different workbooks.

.XLL Add-ins are native code add-ins written in C or C++ programming languages. They offer high performance and direct access to Excel's internal functions, making them suitable for complex and computationally intensive tasks.

The recommended state for this setting is: Enabled: Blocked.

Rationale:

Untrusted XLL files, as dynamic-link libraries (DLLs), pose a security risk in phishing campaigns, where attackers can trick users into executing seemingly harmless files containing malicious payloads. Being executables, XLL files can unwittingly run on users' systems, leading to unauthorized code execution, malware installation, and potential data breaches.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Trust Center\Block Excel XLL Add-ins that come from an untrusted source

Default Value:

Disabled. (Untrusted XLL add-ins are blocked but users can override via the registry.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, 800-53|CM-7(1), CSCv7|2.8

Plugin: Windows

Control ID: f4706bfcaad74e590cbab122f2d46b19fa3ee31ab1bb34caba4b46615155d084