pwshub.com

Microsoft is trying to kill ActiveX controls in Office for good

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

In context: Microsoft introduced ActiveX in 1996 during Windows 95 days. So, in technological terms, it's ancient. Redmond designed it as a developer framework, allowing users to embed interactive objects into Windows applications and Internet Explorer. However, ActiveX eventually became a security threat that the tech giant's engineers are understandably trying to remove.

Despite being nearly 30 years old, Microsoft still supports ActiveX in Windows. Microsoft deprecated the technology long ago, but some of the most popular Win32 applications use it. Cybercriminals also love ActiveX, so Microsoft is taking measures to reduce the attack surface provided by the controversial framework.

The Microsoft 365 Admin Center recently published a warning that developers would soon disable ActiveX controls in Office applications by default. The change will affect Word, Excel, PowerPoint, and Visio. The target date for Office 2024 is October 2024, while Microsoft 365 apps have until April 2025.

Microsoft plans to release the next stand-alone upgrade for Office 2024 this year. The suite's default configuration setting for ActiveX objects will now change from "Prompt me before enabling all controls with minimal restrictions" to "Disable all controls without notification."

Once the changes occur, users can no longer create or interact with ActiveX objects in Office documents. Some existing ActiveX controls will be visible as static images, but no further action will be possible.

There will be no visible indications about the sudden death of ActiveX controls except for non-commercial Office suite SKUs. The new default setting is equivalent to the DisableAllActiveX setting in the Group Policy snap-in tool. However, resourceful users can re-enable ActiveX support in Office using the Group Policy editor, the Registry, and individual Office applications via the Microsoft Office Trust Center.

Widely used in Internet Explorer, ActiveX has long become a risky relic of a bygone technology era. Programmers and companies would be better off replacing and abandoning the framework altogether. Bad actors have abused Windows users by exploiting the many significant security threats ActiveX has presented over the years, including running compiled code within Office documents to install a malware payload targeting corporate networks with relative ease.

Source: techspot.com

Related stories
6 days ago - Some users will see the appeal of Big Red stacking its hardware in Amazon's datacenters Analysis At Big Red's recent CloudWorld shindig in Las Vegas, Matt Garman, CEO of AWS, looked comfortable and relaxed being hosted by arch rival...
1 month ago - Innovation dead for twenty years? Tell that to 2004 Opinion Want a good time on stage, but you’re not a performance artist? Surprisingly easy. Fill a hall with an audience of your peers, tell them the world’s gone to hell in a handcart,...
2 weeks ago - Tucked away in the latest Windows beta builds is an optimized on-screen keyboard layout designed specifically for Xbox controllers. The virtual keys have been realigned vertically to speed up typing. Some handy shortcut buttons have also...
1 month ago - Skype's latest update is now ad-free for users in the Insider program, affecting both the main chat interface and channels.Read Entire Article
3 hours ago - big bucks, no whammies — Investment "goes beyond what any single company or government can...
Other stories
4 minutes ago - Act fast to grab this high-performing mesh router for less than $500, keeping you connected while saving some cash too.
4 minutes ago - If the old-school PlayStation is dear to your heart, you can soon relive those totally sweet 1990s memories. Sony is releasing a series of products...
4 minutes ago - If you've got an old phone to part with, T-Mobile is offering both new and existing customers the brand-new Apple iPhone 16 Pro for free with this trade-in deal.
5 minutes ago - Who doesn't want the best for their beloved pooch? Grab some of these tasty treats to make your dog feel special.
11 minutes ago - To be fair, Joe was probably taking a nap The Iranian cyber snoops who stole files from the Trump campaign, with the intention of leaking those documents, tried to slip the data to the Biden camp — but were apparently ignored, according...