Microsoft explains why Office is the favorite of hackers (ActiveX)

Analysis
Mar 3, 20092 mins

Microsoft is frequently lambasted over flaws found in its most popular enterprise wares. A post today on the Microsoft Research & Defense blog explained why Office has become a hacker favorite … ActiveX controls. These are intended to give Office documents a richer experience when used with the backoffice server by enabling scripting. However some ActiveX controls can be configured to execute without a prompt. The blog states:

Attackers have discovered ActiveX support in Office applications and have been using it to more effectively lure victims to web-based malware. They have recently used the “Microsoft Scriptlet Component” to navigate victims to a website exploiting a patched Internet Explorer vulnerability (CVE 2009-0075, fixed by security bulletin MS09-002). Seems like attackers have discovered it is easier to trick a user to open a Word document attached to email compared to luring a user to click a dubious-looking link. This specific attack is mentioned in a Trend Malware Blog posting last week (https://blog.trendmicro.com/another-exploit-targets-ie7-bug//).

IT professionals can minimize the malicious ActiveX issue by changing Office’s settings so that all ActiveX commands force a prompt — but the setting to do so isn’t obvious. For Office 2007 users, the setting is accessed in the Trust Center. From that screen administrators would need to click on ActiveX Settings and then check mark “Prompt me before enabling all controls with minimal restrictions.” The blog gives step-by-step directions. The help topic “Enable or disable ActiveX controls in Office documents“ gives more detail on configuring ActiveX as well.