• Outlook Forms run VBScript even when macros are disabled

    Home » Forums » Newsletter and Homepage topics » Outlook Forms run VBScript even when macros are disabled

    • This topic has 4 replies, 4 voices, and was last updated 8 years ago.
    Author
    Topic
    #112437

    My question, though, is whether this constitutes a security problem. I’m hoping one of you Office experts can help me out. This morning, Richard Chirg
    [See the full post at: Outlook Forms run VBScript even when macros are disabled]

    1 user thanked author for this post.
    Viewing 2 reply threads
    Author
    Replies
    • #112441

      I remember that VBScript in forms used separate settings. The forms has to be published for VBScript to run by default. There used to be a separate macro warning for VBScript that was disabled by default in the “Outlook email security update” in 2000.

      1 user thanked author for this post.
      • #112460

        The forms has to be published for VBScript to run by default.

        That’s my recollection, too, although I never use Outlook these days – and rarely used forms, even back in my Outlook days.

        If that’s the case, Microsoft’s right, this isn’t a big deal.

    • #112464

      You would have to export the form, get another user to install both files (.frm and .frx) and generate a self signed certificate for themselves.

      Or go to the expense of buying a cert, for distribution – which is not as hard for malware authors as it used to be.

      Either way, I see no way for a drive by infection using this method.

      ~ Group "Weekend" ~

      1 user thanked author for this post.
    • #112912

      Most good AV programs do a good job at scanning for potentially malicious code in vbscript programs, and many AV programs will ask you if you want to allow the vbscript to run.

    Viewing 2 reply threads
    Reply To: Outlook Forms run VBScript even when macros are disabled

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: