silversurfer

Level 78
Verified
Helper
Top poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
6,752
Microsoft has added XLM macro protection for Microsoft 365 customers by expanding the runtime defense provided by Office 365's integration with Antimalware Scan Interface (AMSI) to include Excel 4.0 (XLM) macro scanning. [...]
"The recent AMSI instrumentation in XLM directly tackles the rise of malware campaigns that abuse this feature," Microsoft said.
"Because AMSI is an open interface, other antivirus solutions can leverage the same visibility to improve protections against threats."

AMSI-XLM-instrumentation

Image: Microsoft
"The visibility provided by AMSI leads to significant improvements in generic and resilient signatures that can stop waves of obfuscated and mutated variants of threats," Microsoft added.
 

upnorth

Moderator
Verified
Staff member
Malware Hunter
Well-known
Jul 27, 2015
4,578
We are introducing a change to the Excel Trust Center Macro settings to provide a more secure experience for users by default. This new default behavior will disable Excel 4.0 macros.

Note: Users who have already configured this setting or have a group policy configuration in place will not be affected by this change.
 

silversurfer

Level 78
Verified
Helper
Top poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
6,752
Microsoft will begin disabling Excel 4.0 macros in all tenants using this rollout schedule:
  • Insiders-Slow: will rollout in late October and be complete in early November.
  • Current Channel: will rollout in early November and be complete in mid-November.
  • Monthly Enterprise Channel (MEC): will begin and complete rollout in mid-December.
Microsoft will not be making any changes for users who have manually configured this setting or configured it via group policies.
 
Top