Building custom solutions that extend, automate, and integrate Microsoft 365 apps.
Code Injection from Outlook and Excel
Hi All,
We have observed Outlook and Excel attempted code injection by calling the function "SetWindowsHookExW," resulting in blocks by Carbon Black endpoint protection.
We would like to understand if this behavior is expected and why these applications are attempting code injection.
Alerts:
Outlook: The application "c:\program files\microsoft office\root\office16\outlook.exe" attempted to inject code into the process "c:\program files\microsoft office\root\office16\outlook.exe" by calling the function "SetWindowsHookExW." The operation was blocked by Carbon Black.
Excel: The script "\desktop\file\B_list.xlsx" attempted to inject code into the process "c:\program files\microsoft office\root\office16\excel.exe" by calling the function "SetWindowsHookExW." The operation was blocked by Carbon Black.
Thank you.
Microsoft 365 and Office | Development | Other
Outlook | Windows | Classic Outlook for Windows | For business
Using classic Outlook for Windows in business environments
Microsoft 365 and Office | Excel | For business | Windows
A family of Microsoft spreadsheet software with tools for analyzing, charting, and communicating data