Forum Discussion
Anonymous
Jun 27, 2024ASR rule "Block Win32 API calls from Office macro Block XLS
Hi All, we have deploy defender for Endpoint in customer organization and the rule "ASR rule "Block Win32 API calls from Office macro" block old version of Excel with macro, we set exclusion for a pa...
- Jul 02, 2024Have a look in the Defender logs - i found that once you've unblocked the original file location, Excel starts processing the macros using the local user profile 'Content.MSO' folder, so then you have to consider whether you feel you can unblock that location as well. Not ideal from a security perspective.
Interesting that you found that upgrading the Excel file version made a difference, do you have more details on that?
dedz_st_leonardz
Jul 02, 2024Copper Contributor
Have a look in the Defender logs - i found that once you've unblocked the original file location, Excel starts processing the macros using the local user profile 'Content.MSO' folder, so then you have to consider whether you feel you can unblock that location as well. Not ideal from a security perspective.
Interesting that you found that upgrading the Excel file version made a difference, do you have more details on that?
Interesting that you found that upgrading the Excel file version made a difference, do you have more details on that?
itsmedevil
Sep 25, 2024Copper Contributor
Onen