Microsoft Disables DDE Feature in Word to Prevent Further Malware Attacks

  • 15 December 2017
  • 1 reply
  • 4 views

Userlevel 7
Badge +54
December 15, 2017 By Catalin Cimpanu
 


 
As part of the December 2017 Patch Tuesday, Microsoft has shipped an Office update that disables the DDE feature in Word applications, after several malware campaigns have abused this feature to install malware.
 
DDE stands for Dynamic Data Exchange, and this is an Office feature that allows an Office application to load data from other Office applications. For example, a Word file can update a table by pulling data from an Excel file every time the Word file is opened.
 
DDE is an old feature, which Microsoft has superseded via the newer Object Linking and Embedding (OLE) toolkit, but DDE is still supported by Office applications.
 
Full Article.

1 reply

Userlevel 7
At least Microsoft is on top of this one for a change.

Reply