DTOO146 - Trust access for VBA must be disallowed.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel. By default, Excel, Word, and PowerPoint do not allow automation clients to have programmatic access to VBA projects. Users can enable this by selecting the Trust access to the VBA project object model in the Macro Settings section of the Trust Center. However, doing so allows macros in any documents the user opens to access the core Visual Basic objects, methods, and properties, which represents a potential security hazard.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft Word 2013 -> Word Options -> Security -> Trust Center 'Trust access to Visual Basic Project' to 'Disabled'.

See Also

https://iasecontent.disa.mil/stigs/zip/U_MS_Word_2013_V1R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CCI|CCI-000381, Rule-ID|SV-53576r1_rule, STIG-ID|DTOO146, Vuln-ID|V-17522

Plugin: Windows

Control ID: f83b09e50923c83e0393d5feaef5fff0101b85f523d63cfb14b0e006f1632277