Skip to content
arrow_back
search
ISM-1669 policy ASD Information Security Manual (ISM)

Prevent Microsoft Office from Injecting Code

Microsoft Office is configured to not insert code into other programs for security reasons.

record_voice_over

Plain language

This control is about stopping Microsoft Office from inserting its code into other software on your computer. It matters because if Office could easily inject code elsewhere, it might open the door for hackers to exploit that capability, leading to data theft or malicious software spreading without you knowing.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Microsoft Office is blocked from injecting code into other processes.
policy ASD Information Security Manual (ISM) ISM-1669
priority_high

Why it matters

If Microsoft Office can inject code into other processes, attackers can use Office to run malicious code in trusted apps, enabling malware spread and data compromise.

settings

Operational notes

Enable and audit the Defender ASR rule ‘Block Office applications from injecting code into other processes’, monitor alerts, and restrict any exceptions to approved cases.

Mapping detail

Mapping

Direction

Controls