News: 1644288788

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft to block downloaded VBA macros in Office – you may be able to run 'em anyway

(2022/02/08)


Microsoft Office will soon block untrusted Visual Basic for Applications (VBA) macros sourced from the internet by default – a security measure users can still circumvent, permissions allowing.

The Windows giant [1]announced that the change will come in version 2203 of Office for Windows, due in April 2022, and applies to Access, Excel, PowerPoint, Visio, and Word. The change will come to Office LTSC, Office 2021, Office 2019, Office 2016, and Office 2013 at a date to be determined.

Microsoft's rationale for the change is that criminals use macros to target users, and that Office's current defense strategy is somewhat lacking.

[2]

It's important to note that, plus or minus some caveats, users will still be able to override Microsoft’s ban, because when they open a document containing an untrusted macro from the internet, they'll see the message below explaining why it won't run:

[3]

Microsoft’s macro missive

Note the presence of that "Learn More" button, dear readers. It opens a [4]document Microsoft has penned for folks to explain its macro rules. That document also explains how to save the blocked macro to a local drive and change its permissions to allow it to run and circumvent the block.

Another important point to note, though, is that IT admins can use an Office cloud policy or an ADMX or group policy to prevent users from overriding the above warning and just stop the unsafe content dead. Microsoft's [5]advice for Office admins states that users should only side-step the block "if absolutely needed."

[6]

[7]

Redmond's announcement quotes Tristan Davis, Microsoft's partner group program manager for the Office Platform, saying: "We will continue to adjust our user experience for macros, as we've done here, to make it more difficult to trick users into running malicious code via social engineering while maintaining a path for legitimate macros to be enabled where appropriate via Trusted Publishers and/or Trusted Locations."

Those are The Register 's italics.

[8]Command 'n' control botnet of notorious Emotet Windows ransomware shut down in multinational police raid

[9]Lock up your Office macros: Emotet botnet back from the dead with Trickbot links

[10]Eight-year-old bug in Microsoft's 64-bit VBA prompts complaints of neglect

[11]Microsoft doc formats are the bane of office suites on Linux, SoftMaker's Office 2021 beta may have a solution

Another thing to watch for is that the mechanism Microsoft is using to enforce the block won't work if you're using a FAT32 filesystem for some reason.

That mechanism is called Mark Of The Web (MOTW) and is derived from tech that Microsoft's abandoned Internet Explorer web browser used to classify the source of a document so it could apply appropriate levels of security. MOTW works by adding an attribute to files as they arrive on a device – but as Microsoft's announcement of the macro ban explains, that attribute only sticks on files saved to a NTFS file system. Files on FAT32 formatted devices don't get MOTW info.

[12]

For those of you using NTFS and cloudy controls for Office management, here's how the macro-filtering process works:

[13]

Click to enlarge

Macros have been a well-known menace ever since [14]the ILOVEYOU worm erupted onto millions of PCs in May 2000. Redmond's minions have tried to make life harder for authors of malicious macros ever since, though those efforts appear not to have deterred macro-centric malware authors. Tom Gallagher, partner group engineering manager for Office Security, admits that "a wide range of threat actors continue to target our customers by sending documents and luring them into enabling malicious macro code."

Those miscreants may now find it harder to succeed, though they've also been given a strong signal that now is the time to figure out how to game MOTW. They also know that come April 2022 they should ignore the population of users that run the one version of Office that will ban macros, and that it may be worth developing new social engineering tactics for that group of users. ®

Get our [15]Tech Resources



[1] https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YgH49v5ccUiKeIDtxefvwgAAAEM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://regmedia.co.uk/2022/02/07/supplied_microsoft_macro_warning.jpg

[4] https://support.microsoft.com/en-us/topic/a-potentially-dangerous-macro-has-been-blocked-0952faa0-37e7-4316-b61d-5b5ed6024216

[5] https://docs.microsoft.com/en-us/DeployOffice/security/internet-macros-blocked

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgH49v5ccUiKeIDtxefvwgAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YgH49v5ccUiKeIDtxefvwgAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2021/01/27/emotet_botnet_taken_down_europol/

[9] https://www.theregister.com/2021/11/16/emotet_botnet_rappears/

[10] https://www.theregister.com/2021/08/19/64_bit_microsoft_vba_bug/

[11] https://www.theregister.com/2020/05/12/softmaker_office_2021_microsoft_document/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgH49v5ccUiKeIDtxefvwgAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://regmedia.co.uk/2022/02/08/supplied_microsoft_macro_assessment_flowchart.png

[14] https://www.theregister.com/2020/05/05/iloveyou_20_years/

[15] https://whitepapers.theregister.com/



FAT32?

WolfFan

The only FAT32 devices around here are thumb drives, the first thing that I do to FAT formatted hard drives is to reformat them for Mac or NTFS or something Linuxy. Windows hasn’t booted from FAT32 since Vista, officially since XP, but you could make Vista boot if you REALLY pushed it. As far as I know Win 7 requires NTFS. Macs don’t boot from FAT file systems and never have, and Office doesn’t run on Linux. So far as I can see, this is a problem only if users are saving directly unto thumb drives.

A tighter security method.

ShadowSystems

Don't use MS Office. There are plenty of third party alternatives out there, both free & paid, so go visit DDG & hunt for something better than the crap MS is shoveling.

Dear Microsoft, there is no hatred greater than a previous FanBoy turned to a mortal enemy by your own hand.

You hit me with the Ribbon, Win8, Win10, and now Win11 on an epic trainwreck clusterfuck of fail. You have only yourselves to blame given how badly you've jumped the rails & plowed that juggernaught over a cliff.

Re: A tighter security method.

Foxglove

Thank you ShadowSystems for the wonderful phrase:

'an epic trainwreck clusterfuck of fail'

I hope you don't mind me nicking that, 'cos I already have.

Sadly corporate policy requires use of MS products (including Teams - shiver of horror goes down my spine) so I have to suck it up.

Have a beer mate!

For some reason a glaze passes over people's faces when you say
"Canada". Maybe we should invade South Dakota or something.
-- Sandra Gotlieb, wife of the Canadian ambassador to the U.S.