“The previous default setting, ‘Prompt me before enabling all controls with minimal restrictions,’ allowed you to enable potentially dangerous ActiveX controls, which attackers could exploit through social engineering or malicious files,” said Zaeem Patel, Product Manager on the Office Security team. “Making its subscription customers wait just a little longer for better security is emblematic of Microsoft’s cautious, phased approach to flensing its flagship software of insecure features,” notes a security analysis from ThreatDown. When users open a document containing ActiveX controls, they’ll now see a notification banner stating “BLOCKED CONTENT: The ActiveX content in this file is blocked,” with an option to learn more. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. This significant security update, which began rolling out earlier this month, aims to reduce the risk of malware and unauthorized code execution that has long plagued the legacy technology.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 15 Apr 2025 14:30:19 +0000