UCF STIG Viewer Logo

Scan of encrypted macros in Excel Open XML workbooks must be enabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-223333 O365-EX-000024 SV-223333r508019_rule Medium
Description
This policy setting controls whether encrypted macros in Open XML workbooks be are required to be scanned with anti-virus software before being opened. If you enable this policy setting, you may choose one of these options: - Scan encrypted macros: encrypted macros are disabled unless anti-virus software is installed. Encrypted macros are scanned by your anti-virus software when you attempt to open an encrypted workbook that contains macros. - Scan if anti-virus software available: if anti-virus software is installed, scan the encrypted macros first before allowing them to load. If anti-virus software is not available, allow encrypted macros to load. - Load macros without scanning: do not check for anti-virus software and allow macros to be loaded in an encrypted file. If you disable or do not configure this policy setting, the behavior will be similar to the "Scan encrypted macros" option.
STIG Date
Microsoft Office 365 ProPlus Security Technical Implementation Guide 2022-06-17

Details

Check Text ( C-25006r442218_chk )
Verify the policy value for User Configuration >> Administrative Templates >> Microsoft Excel 2016 >> Excel Options >> Security >> Scan encrypted macros in Excel Open XML workbooks is set to "Scan encrypted macros (default)".

Use the Windows Registry Editor to navigate to the following key:

HKCU\software\policies\microsoft\office\16.0\excel\security

If the value excelbypassencryptiedmacrosscan does not exist, this is not a finding.

If the value for excelbypassencryptedmacroscan is REG_DWORD = 0, this is not a finding.
Fix Text (F-24994r442219_fix)
Set policy value for User Configuration >> Administrative Templates >> Microsoft Excel 2016 >> Excel Options >> Security >> Scan encrypted macros in Excel Open XML workbooks to "Scan encrypted macros (default)".