This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Microsoft Power Query for Excel - False Flagging by Intercept/Crashes Excel

We have a few users that have Microsoft Power Query for Excel installed.  Whenever they enabled the add-in it crashes Excel.  If we disable Sophos Intercept it works just fine.  I can't seem to find where I can whitelist this COM Add-In.  Any ideas?  Sophos continually flags this in RCA as 'Exploit CallerCheck'.



This thread was automatically locked due to age.
Parents Reply
  • Hi SecBug

    I have put a Scanning Exclusion in place, which does not fix the issue.

    As I said I do have a ticket open with support, they've sent me a test build (hasn't fixed the issue) and asked for some SDU logs.

    One thing that does work is adding Excel in the Exploit Mitigation Exclusion.

    Given that a lot of viruses are spread through Excel macros this isn't a brilliant solution, also this option is only available as a Global system setting and not as a Policy setting I could apply only to certain users to reduce the risk slightly?

Children
  • Same problem here ...  Excel 2010 with Power Query.  Sophos gives a false positive when I try to connect to an internal database.  Adding Excel in exploit exclusion is not an option, this is the reason why we use sophos to discover strange behavour of files.

    Is there already a solution provided ?