After the release of Office 2024 in October, Microsoft will disable ActiveX controls by default in the Word, Excel, PowerPoint, and Visio client applications.
See also: Microsoft Office: Pirated versions distribute malware

ActiveX is a legacy software framework introduced in 1996 that allows developers to create interactive objects that can be embedded in Office documents. The company will begin disabling ActiveX controls in documents opened in Win32 Office desktop applications in October 2024 , a change that will also roll out to Microsoft 365 apps in April 2025 .
“Starting in the new Office 2024, the default configuration setting for ActiveX objects will change from Prompt me before enabling all controls with minimal restrictions to Disable all controls without notification,” said in a new Microsoft 365 message center entry.
While some existing ActiveX objects will continue to appear as static images in Microsoft Office documents, users will no longer be able to interact with them.
However, in non-commercial versions of Office, they will receive notifications like: “The new default setting is equivalent to the existing DisableAllActiveX Group Policy setting” when ActiveX objects are blocked with the new default configuration.
Once the change is implemented, users who need to enable ActiveX controls in Office documents can revert to the previous default settings by using one of the following methods:
See also: Attacks against Ukraine via old Microsoft Office vulnerability
- In the Trust Center Settings dialog box, under ActiveX Settings, select the "Prompt me before enabling all controls with minimal restrictions" option.
- In the registry, set HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Security\DisableAllActiveX to 0 (REG_DWORD).
- Set the " Disable all ActiveX " group policy setting to 0 .

This change was likely caused by known ActiveX security issues, such as zero-day vulnerabilities exploited by North Korean hackers Andariel to develop malware that steals Microsoft Office information.
Attackers have also used ActiveX controls embedded in Word documents to install TrickBot and Cobalt Strike to infiltrate corporate networks.
The move is part of a broader effort to remove or disable features in Office and Windowsthat have been abused by threats to infect Microsoft customers with malware. It dates back to 2018, when Microsoft expanded support for the Antimalware Scan Interface (AMSI) to Office 365 client applications to prevent attacks that used Office VBA macros.
See also: Microsoft Office LTSC 2024 Preview Available
ActiveX is a Microsoft Office software framework that enables the integration of interactive content into applications, primarily web browsers. By enabling various components, ActiveX controls facilitate dynamic functionality, such as multimedia presentations, complex data manipulation, and enhanced user interactions. While it played an important role in the early days of web development, the use of ActiveX has declined with the rise of modern web standards and security concerns , as many browsers no longer support it. However, ActiveX remains a topic of interest for legacy applications, particularly in enterprise environments where specific functionality is still required .
Source: bleepingcomputer
