2.2.4.7.2.13 Ensure 'Trust access to Visual Basic Project' is set to 'Disabled'

Information

This policy setting controls whether automation clients such as Microsoft Visual Studio 2005 Tools for Microsoft Office (VSTO) can access the Visual Basic for Applications project system in the specified applications. VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel.

The recommended state for this setting is: Disabled.

Rationale:

VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel.

Impact:

None - this is the default behavior.

By default, Excel, Word, and PowerPoint do not allow automation clients to have programmatic access to VBA projects. Users can enable this by selecting the Trust access to the VBA project object model in the Macro Settings section of the Trust Center. However, doing so allows macros in any documents the user opens to access the core Visual Basic objects, methods, and properties, which represents a potential security hazard.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled.

User Configuration\Administrative Templates\Microsoft Excel 2016\Excel Options\Security\Trust Center\Trust Access To Visual Basic Project

Default Value:

Disabled. (Client access to VBA projections is not allowed but users can override.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 29d7ee4b1943e06da8ecf31d3b700bd53984809ebc3fba98517bbf51f9d356b9