Skip to main content

Office DDE attack works in Outlook too – here’s what to do

  • October 22, 2017
  • 2 replies
  • 5 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
See Also - Unpatched Microsoft Word DDE Exploit Being Used In Widespread Malware Attacks
 
22nd October 2017  By Bill Brenner
 


 
In the last two weeks, Sophos researchers have kept an eye on a vulnerability in Microsoft’s Dynamic Data Exchange (DDE) protocol used to send messages and share data between applications.
 
Yesterday, new developments revealed an additional dimension to this attack.
 
Early on, we noted that attackers could exploit DDE to launch malware via tainted Office attachments, for example in Word and Excel files, but without using macros. 
 
On Friday, independent reports surfaced showing that it’s possible to run DDE attacks in Outlook using emails and calendar invites formatted using Microsoft Outlook Rich Text Format (RTF), not just by sending Office files attached to emails.
 
Full Article.

2 replies

  • Community Guide
  • October 22, 2017
So...................what's the answer to this one?? So don't use Outlook using emails and calendar invites????

Forum|alt.badge.img+48
  • Retired Webrooter
  • October 23, 2017
Yikes. That's going to be tough ;)