Microsoft changes its mind on blocking Office macros once again

A computer screen showing a spreadsheet in use.
(Image credit: 123RF)

Microsoft’s decision not to block Visual Basic for Applications (VBA) macros by default in Office applications is only temporary, as the company still plans on going through with the plan.

In a blog post updated last week, Microsoft principal product manager, Kellie Eickmeyer noted that, “Following user feedback, we have rolled back this change temporarily while we make some additional changes to enhance usability. 

"This is a temporary change, and we are fully committed to making the default change for all users.” 

Abusing macros

While Microsoft did not go into details on what that specific user feedback was, and what it plans on doing next, reports have said the issue is one of user training. 

The company reportedly planned to have Office users enable macros by specifically needing to unblock the option in the file’s properties. These steps, it claims, will require user training, which is something Microsoft is now allegedly looking to simplify.

Right now, enabling macros is just one click away, as the option is served as a prompt in the upper part of the app. Microsoft’s plan was to replace this feature with a link, sending users to a support website holding the instructions. 

Macros allow Office files to download files from the internet and run arbitrary code, and as such have been the perfect tool for cybercriminals looking to compromise corporate networks. Companies responded by tightening up their defenses with antivirus solutions, firewalls, employee training, and security keys.

They’ve been so successful in abusing the functionality that Microsoft was eventually forced to shut it down, completely.

The change was scheduled to go live last month before Microsoft abruptly decided to postpone. Sme users were not satisfied with the change, saying that it won’t help improve the security posture, but rather expose user endpoints to even more risk.

Via: The Verge

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Phone scammer
Microsoft thinks it could stop this dangerous scam forever
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Microsoft is changing the way logins work: here’s what that means for you
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
Avast cybersecurity
Amazon pauses $1bn Microsoft 365 rollout following Russian security concerns
Woman using a Windows computer with Microsoft Edge
Don’t panic – Microsoft’s Edge browser isn’t about to subject you to a flood of unblocked adverts (not yet, anyway)
Latest in Security
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
Latest in News
Google Gemini Robotics
Gemini just got physical and you should prepare for a robot revolution
Lilo & Stitch Official Trailer
Stitch crashes into earth and steals our hearts with the first trailer for the live-action Lilo & Stitch
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
Y2K cast looking shocked
Y2K has a streaming release date on Max, so you can witness the technology uprising at home
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'