This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos cloud endpoint: Multiple users getting "Caller Check Exploit Prevented in Microsoft Excel" when using custom spreadsheets

I need a resolution for this false positive that does not completely whitelist Excel.

This is directly relevant to the following thread:

https://community.sophos.com/intercept/f/information/82464/microsoft-power-query-for-excel---false-flagging-by-intercept-crashes-excel

This was supposed to be resolved by the end of November. 

We need a resolution now.

 



This thread was automatically locked due to age.
Parents Reply Children
  • This is causing issues for us also.

    Excel 2016 x64

    Have had to create a "wide open" exception. There needs to be a whitelist of allowed "URL's" that Excel can query. 

     

  • Just FYI there is a fix coming. I have been working with them to get this working. As it stands the latest version of Sophos includes this fix. The thumbprint of the event stays the same now allowing that exploit itsself to be added to the exceptions list. However for me it still remains an issue. I'm waiting to hear back from Sophos about this. As soon as i've got it working i will share the great news.