Microsoft to disable old-school macros to shield users from attacks


Microsoft has revealed its plan to disable Excel 4.0 macros or XLM macros for all Microsoft 365 users in a recent email sent out to its customers.
First introduced back in 1992 with the release of Excel 4.0, XLM macros allow users of the company’s spreadsheet software to enter complex formulas inside Excel cells capable of executing commands both in the program itself and in a Windows computer’s local file system. Although XLM macros were replaced by VBA-based macros when Excel 5.0 was released, Microsoft has continued supporting this legacy feature over the years.
Although macros are convenient for Excel users, they have also been repeatedly abused by cybercriminals in their attacks. This is because, once enabled in a malicious document, they can give a threat actor additional control over a user’s system to install malware or carry out other attacks.
With more people working from home than ever before last year, there was a huge uptick in the number of malware strains and cybercriminals abusing XLM macros in their attacks. Things got so bad that Microsoft even went to the trouble of adding XLM macro support to Microsoft 365’s Antimalware Scan Interface (AMS) in March of this year in an effort to help antivirus software deal with these kinds of attacks.
Disabled by default
Following request from software companies that XLM Macros be disabled by default inside its office software, Microsoft is now tackling the issue head on.
In a recent email sent to Microsoft 365 customers, the company laid out its plan to disable the feature across three stages according to The Record. The feature will be disabled by default for Microsoft 365 Insiders beginning at the end of this month, those on the current channel will see it disabled in early November and the Monthly Enterprise Channel (MEC) will have XLM macros disabled by default in December.
These efforts may not be enough for security researchers though as they are now asking Microsoft to also disable VBA macros as default.
If you want XLM macros disabled now, you should check out this support document from Microsoft which lays out exactly how to remove the feature from Excel.
Via The Record
Microsoft has revealed its plan to disable Excel 4.0 macros or XLM macros for all Microsoft 365 users in a recent email sent out to its customers. First introduced back in 1992 with the release of Excel 4.0, XLM macros allow users of the company’s spreadsheet software to enter complex…
Recent Posts
- Razer’s new Blade 18 offers Nvidia RTX 50-series GPUs and a dual mode display
- I tried adding audio to videos in Dream Machine, and Sora’s silence sounds deafening in comparison
- Sandisk quietly introduced an 8TB version of its popular portable SSD, and I just hope they solved its previous big data corruption issue
- iPhones are briefly changing ‘racist’ to ‘Trump’ due to an iOS dictation issue
- We finally know who’s legally running DOGE
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010