What is the XLM file format?
.xlm is a legacy Excel macro sheet introduced with Microsoft Excel 4.0 in 1992. It stores spreadsheet-style macro programs written in the XLM macro language - a formula-based scripting system that predates Visual Basic for Applications (VBA) by one Excel generation. Each macro function occupies a worksheet cell, making macros visible as a grid of instructions rather than a separate code module.
Internally, .xlm files use the OLE2 Compound File Binary (CFBF) container, sharing the classic D0 CF 11 E0 magic-byte header with .xls, .doc, and .ppt files. The macro data lives inside a BIFF stream flagged as a macro sheet; no unique magic number distinguishes .xlm from a plain workbook, so identification depends on that internal stream flag.
VBA replaced XLM in Excel 5.0 (1993), and the format has been frozen ever since. Microsoft still supports XLM execution for backward compatibility, but blocked XLM macros by default in Excel beginning in 2021 following a wave of malware campaigns (approximately 2018-2020) that weaponized the format to evade defenses tuned specifically for VBA.
Today, XLM payloads appear more often embedded inside .xlsm or .xlsb workbooks than as standalone .xlm files. A malicious sheet can invoke Excel built-in macro functions such as EXEC and CALL to run arbitrary system commands without triggering VBA-focused scanners. Open an .xlm file only from a fully trusted source.
Security & safety
RISK: HIGHExcel 4.0 (XLM) macros are a well-documented malware delivery vector. Because they predate VBA, they were used 2018-2021 to evade antivirus and drop banking trojans and ransomware loaders, typically auto-running via an Auto_Open macro the moment the workbook opens. Rules for users: never enable macros in an .xlm (or macro-laden .xls/.xlsm) you didn't expect; keep Excel's Trust Center set to block Excel 4.0 macros (default in current Excel since 2021); open suspicious files in Protected View or an isolated VM; analysts can use oletools (olevba) and XLMMacroDeobfuscator to extract the macro code without executing it. A loose .xlm arriving by email/chat should be treated as hostile until proven otherwise.
Format details
in a nutshellPrograms that open XLM files
Technical details
deep spec| Container format | OLE2 Compound File Binary Format (CFBF) |
| Internal stream format | BIFF (Binary Interchange File Format) records inside a 'Workbook'/'Book' stream |
| Byte order | Little-endian |
| Encoding | Binary (BIFF records) |
| Magic bytes | D0 CF 11 E0 A1 B1 1A E1 at offset 0 (shared OLE2/CFBF header) |
| MIME type | application/vnd.ms-excel |
| Macro language | Excel 4.0 XLM - formula-based, cell-resident; each macro instruction is a worksheet cell value |
| Security classification | High risk - XLM macro execution blocked by default in Microsoft Excel since 2021 |
| Notable dangerous functions | EXEC, CALL, REGISTER, RUN - can invoke arbitrary OS commands from within the macro sheet |
| Developer | Microsoft |
| Superseded by | VBA macros (.xlsm / .xlsb workbooks), introduced in Excel 5.0 (1993) |
| Supported platforms | Windows (all modern Excel), macOS (Excel for Mac); read support in LibreOffice Calc |
| Typical file size | A few KB to a few hundred KB |
| Compression | None - BIFF records are stored uncompressed |
| Encryption support | Optional; password-protected workbooks may use RC4 or AES encryption around the OLE2 container |
| Macro execution model | Macros stored as cell formulas in a dedicated macro sheet tab; evaluated top-to-bottom by the Excel calculation engine |
| Released | 1992 (Excel 4.0 macro language, .xlm macro-sheet files) |
| Latest version | Excel 4.0 macro language (frozen 1992); never updated - superseded by VBA in Excel 5.0 (1993) |
| Specification | learn.microsoft.com |
XLM conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about XLM files.