Check: DTOO145 - Excel
Microsoft Excel 2010:
DTOO145 - Excel
(in version v1 r2)
Title
Macro storage must be in Personal macro workbooks. (Cat II impact)
Discussion
The Record Macro dialog box includes a drop-down menu allowing users to choose whether to store the new macro in the current workbook, a new workbook, or their personal macro workbook (Personal.xlsb), a hidden workbook that opens every time Excel starts. By default, Excel displays the Record Macro dialog box with “This Workbook already selected” in the drop-down menu. If a user saves a macro in the active workbook and then distributes the workbook to others, the macro is distributed along with the workbook, which could put workbook data at risk if the macro is triggered accidentally or intentionally.
Check Content
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft Excel 2010 -> Excel Options -> Security -> Trust Center “Store macro in Personal Macro Workbook by default” to “Enabled”.
Additional Identifiers
Rule ID: SV-33443r1_rule
Vulnerability ID: V-17804
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |