Microsoft Office is finally blocking dangerous macros, which could potentially harm your computer and your data. This is a huge step in protecting users from malicious macros, and it’s something that Microsoft has been working on for years. The macro blocker is currently available in the Office 365 subscription service and in the Microsoft Edge browser. It’s available to anyone who has an account with either of those services. If you don’t have an Office 365 subscription or if you use a different browser, you can still try out the macro blocker by downloading it from the Microsoft website. The blocker will be available as a free download on both Windows and MacOS platforms.
BleepingComputer reports that Microsoft has resumed rolling out a long-awaited change in Microsoft Office, which automatically blocks VBA macros in documents that have been downloaded from the internet. The feature was put on hold in early July, which Microsoft says was due to negative feedback. The company has now “made updates to both our end user and our admin documentation to make clearer what options you have for different scenarios.”
Visual Basic for Applications (VBA) macros, which are available on the Mac and Windows versions of Office (not mobile or web), date all the way back to Office 97. They can be used to automate document editing and interface with the underlying operating system, and to send data between Office applications. The unrestricted nature of macros, combined with the popularity of Office applications, has made them a popular choice for malware distribution. For example, a computer can be compromised if someone downloads a Word document and allows the macro to run when prompted.
After the new security feature is rolled out, macros in downloaded documents will be automatically blocked in Excel, PowerPoint, Word, Visio, and Access. Microsoft previously said it would roll out the change across all currently supported versions of Office, including Office LTSC, Office 2021, Office 2019, Office 2016, and Office 2013.
There’s no specified date for when the change will be rolled out to everyone, but it should happen soon. Microsoft is also allowing administrators to change the behavior for their organizations, so if you use Office at work or school, it may behave differently (or already block macros).
Source: BleepingComputer