2.2.4.7.6 Ensure 'WEBSERVICE Function Notification Settings' is set to 'Enabled: Disable all without notification'

Information

This policy setting controls how Excel will warn users when WEBSERVICE functions are present.

When selecting the option 'Disable all with notification' the application displays the Trust Bar for all WEBSERVICE functions. This option enforces the default configuration in Office.

The recommended state for this setting is: Enabled: Disable all without notification.

Rationale:

WEBSERVICE functions can be used alongside of formula injection to cause users of an Excel spreadsheet to unknowingly connect to systems controlled by bad actors, or even exfiltrate data.

Impact:

Users will not be notified when a WEBSERVICE function is disabled.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Disable all without notification.

User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\WEBSERVICE Function Notification Settings

Default Value:

Disabled. (WEBSERVICE functions are disabled, but can be enabled via the Trust Bar by an end user.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 8cd5f4839b466d072b0b6a0e690346793825f808034c2c530e68555533987b2b