Category: Microsoft|Apr 24, 2025 | Author: Admin

Microsoft blocks ActiveX by default in Microsoft 365, Office 2024

Share on

Microsoft announced it will begin disabling all ActiveX controls in Windows versions of Microsoft 365 and Office 2024 applications later this month.

Microsoft blocks ActiveX by default in Microsoft 365, Office 2024

Introduced almost three decades ago, in 1996, ActiveX is a legacy software framework enabling developers to create interactive objects embedded in Office documents.

 

After this change rolls out, ActiveX will be blocked entirely and without notification in Word, Excel, PowerPoint, and Visio to reduce the risk of malware or unauthorized code execution.

 

When opening documents with ActiveX controls, a notification will appear at the top with a "Learn More" button saying, "BLOCKED CONTENT: The ActiveX content in this file is blocked."

 

Microsoft also warned Office users in a separate support document not to open unexpected file attachments or change ActiveX settings when prompted by random pop-ups and unknown people.

 

"When ActiveX is disabled, you will no longer be able to create or interact with ActiveX objects in Microsoft 365 files. Some existing ActiveX objects will still be visible as a static image, but it will not be possible to interact with them," said Zaeem Patel, a product manager on the Office Security team.

 

​Microsoft says that those who want to enable ActiveX controls can do so via the Trust Center by going through the following steps (but it's important to note that this will enable ActiveX across all Office apps, including Word, PowerPoint, Excel, and Visio):

 

  1. Select File, then Options.

  2. Select Trust Center, then the Trust Center Settings button.

  3. Select ActiveX Settings, then ensure "Prompt me before enabling all controls with minimal restrictions" is enabled.

  4. Select OK, then OK again to save your settings and return to your document.

 

"For optimal security, Microsoft strongly encourages leaving ActiveX controls disabled unless absolutely necessary," Microsoft cautioned.

 

The decision to disable it by default was likely prompted by ActiveX's well-known security issues, including zero-day vulnerabilities that were exploited by various state-backed and financially motivated threat groups to deploy malware.

 

Cybercriminals have also used ActiveX controls embedded in Word documents to install TrickBot malware and Cobalt Strike beacons to breach and maintain access to enterprise networks,

 

This move is also a much broader effort to remove or turn off Windows and Office features that attackers have abused to infect Microsoft customers with malware. It goes back to 2018 when Microsoft expanded support for its Antimalware Scan Interface (AMSI) to Office 365 client apps to thwart attacks using Office VBA macros.

 

Since then, Redmond has also started blocking VBA Office macros by default, introduced XLM macro protection, disabled Excel 4.0 (XLM) macros, and began blocking untrusted XLL add-ins by default across Microsoft 365 tenants. Microsoft also announced in May 2024 that it would kill off VBScript by making it an on-demand feature until it is completely removed.

Sponsored Ads:

Comments:


Cloudflare-12-06-25.png

Google Cloud and Cloudflare hit by widespread service outages

Category: IT|Jun 12, 2025 | Author: Admin
Outlook-11-06-25.png

Microsoft Outlook to block more risky attachments used in attacks

Category: Microsoft|Jun 11, 2025 | Author: Admin
Google_headpic-10-06-25.png

Google patched bug leaking phone numbers tied to accounts

Category: Google|Jun 10, 2025 | Author: Admin
Vodafone-headpic-09-06-25.png

Germany fines Vodafone $51 million for privacy, security breaches

Category: IT|Jun 9, 2025 | Author: Admin
Microsoft_logo-08-06-25.png

Microsoft unveils free EU cybersecurity program for governments

Category: Microsoft|Jun 8, 2025 | Author: Admin
FBI__headpic-07-06-25.jpg

Play ransomware breached 900 victims, including critical orgs

Category: IT|Jun 7, 2025 | Author: Admin
Cisco-06-06-25.png

Cisco warns of ISE and CCP flaws with public exploit code

Category: IT|Jun 6, 2025 | Author: Admin
Tu-160_strategic_bomber_aircraft-05-06-25.png

Ukraine claims it hacked Tupolev, Russia’s strategic warplane maker

Category: General|Jun 5, 2025 | Author: Admin
salesforce-04-06-25.png

Hackers target Salesforce accounts in data extortion attacks

Category: Google|Jun 4, 2025 | Author: Admin
logo.png

Mozilla launches new system to detect Firefox crypto drainer add-ons

Category: IT|Jun 3, 2025 | Author: Admin
Google_Chrome-02-06-25.png

Google Chrome to distrust Chunghwa Telecom, Netlock certificates in August

Category: Google|Jun 2, 2025 | Author: Admin
Cisco-logo-01-06-25.png

Exploit details for max severity Cisco IOS XE flaw now public

Category: IT|Jun 1, 2025 | Author: Admin
firefox-header-31-05-25.png

Mozilla releases Firefox 139.0.1 update to fix artifacts on Nvidia GPUs

Category: IT|May 31, 2025 | Author: Admin
microsoft-notepad-30-05-25.png

Microsoft now testing Notepad text formatting in Windows 11

Category: Microsoft|May 30, 2025 | Author: Admin
Windows_11_headpic-29-05-25.png

Windows 11 might fail to start after installing KB5058405

Category: Microsoft|May 29, 2025 | Author: Admin
more