Microsoft starts blocking VBA macro scripts by default in Excel, PowerPoint, Access, Visio, and Word, after years of security experts requesting the change
Catalin Cimpanu / The Record :
Context & Ripple Effects
Microsoft’s move addresses an attack path already visible in related coverage: Chimborazo distributed a malicious Excel document designed to evade automated detection, while an earlier researcher used Word macros to bypass Windows 10 S protections.
The policy’s later rollout history shows the operational trade-off behind the change: Microsoft withdrew the default block after user feedback before resuming it for downloaded Office documents.
First-order effects
- Users of Excel, PowerPoint, Access, Visio, and Word face a more restrictive default for VBA macros, reducing the immediate reach of macro-enabled documents.
- Microsoft takes responsibility for balancing the new protection against the workflow disruption that later prompted its rollback.
Second-order effects
- Attackers using malicious Office files, including the delivery pattern associated with Chimborazo, lose a lower-friction route to getting VBA code executed by recipients.
- Organizations that depend on VBA-enabled documents must adapt document-handling practices, making compatibility feedback a material input to Microsoft’s rollout.
Third-order effects
- The rollback-and-resumption sequence points to Office security moving toward safer defaults, with deployment controls adjusted when enterprise usability conflicts emerge.
- If that pattern holds, protection against document-borne attacks will increasingly be set through centrally shipped product defaults rather than left to individual user judgment.
The trend: Microsoft is using its Office distribution and update controls to make historically abused document features opt-in rather than default behavior.