PSA: Turning off silent macros in Office for Mac leaves users wide open to silent macro attacks

PSA: Turning off silent macros in Office for Mac leaves users wide open to silent macro attacks

Microsoft seems a bit hazy on what 'disable' actually means


A security hole in Office for Mac can be exploited by miscreants to potentially run malicious code on victims' shiny computers without anyone noticing.


The CERT Coordination Center at Carnegie Melon University, on the US East Coast, warns the bug arises when folks activate the "disable all macros without notification" option in Office for Mac. This itself is a good security move, in that it's supposed to block code embedded in documents from running without first asking the user for approval.


However, with this setting switched on, one type of macro, XLM, remains enabled, and will run without any notification when a document is opened, CERT has warned.


"If Office for the Mac has been configured to use ..

Support the originator by clicking the read the rest link below.