vulnerability

Microsoft ADV170021: Microsoft Office Defense in Depth Update

Severity
8
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:N)
Published
Dec 12, 2017
Added
Dec 12, 2017
Modified
Feb 18, 2025

Description

Microsoft has released an update for Microsoft Office that provides enhanced security as a defense-in-depth measure. The update disables the Dynamic Data Exchange protocol (DDE) in all supported editions of Microsoft Word.
Microsoft is continuing to investigate this issue and will update this advisory as further updates become available. If you are unable to install the update, or if you need to disable the DDE protocol in other Office applications, see Microsoft Security Advisory 4053440. Note that the mitigations listed in the advisory will not disable DDE, but will disable auto-update for any linked fields, including DDE.
If you need to change DDE functionality in Word after installing the update, follow these steps:

In the Registry Editor navigate to \HKEY_CURRENT_USER\Software\Microsoft\Office<version>\Word\Security
AllowDDE(DWORD)
Set the DWORD value based on your requirements as follows:

AllowDDE(DWORD) = 0: To disable DDE. This is the default setting after you install the update.
AllowDDE(DWORD) = 1: To allow DDE requests to an already running program, but prevent DDE requests that require another executable program to be launched.
AllowDDE(DWORD) = 2: To fully allow DDE requests.

**Update: ** On 1/9/2018, Microsoft released an update for Microsoft Office that adds defense-in-depth configuration options to selectively disable the DDE protocol in all supported editions of Microsoft Excel.
If you need to change DDE functionality in Excel after installing the update, follow these steps:

In the Registry Editor navigate to \HKEY_CURRENT_USER\Software\Microsoft\Office<version>\Excel\Security
DisableDDEServerLaunch(DWORD)
Set the DWORD value based on your requirements as follows:

DisableDDEServerLaunch = 0: Keep DDE server launch settings unchanged from their initial behavior. This is the default setting after you install the update.
DisableDDEServerLaunch = 1: Do not display the dialog that allows users to choose whether to launch a specific DDE server. Instead, behave automatically as though the user chose the default choice of NO.

In the Registry Editor navigate to \HKEY_CURRENT_USER\Software\Microsoft\Office<version>\Excel\Security
DisableDDEServerLookup(DWORD)
Set the DWORD value based on your requirements as follows:

DisableDDEServerLookup = 0: Keep DDE server lookup settings unchanged from their initial behavior. This is the default setting after you install the update.
DisableDDEServerLookup = 1: Disable querying for DDE Server availability – no query attempt will be made to find DDE servers.
.

Solutions

msft-kb4011590-bc12ce88-f8f7-4c5b-9b68-e39fb7b58156msft-kb4011590-e71fafa0-9d15-478f-9486-60db31d2325cmsft-kb4011602-2b233136-5e49-457a-81f9-f81774776aecmsft-kb4011605-c77fd586-bd96-4165-b594-ffbc1272aea1msft-kb4011606-33d03608-2a03-4917-932c-14cbc3d819eemsft-kb4011608-1e5d7289-59aa-43f3-b8ec-d2a9554efbdbmsft-kb4011612-8230d598-8ab1-4efc-89b6-d3507a6dfd20msft-kb4011612-8c0e84f3-1d9c-4794-b5e5-639c12f3f87bmsft-kb4011614-18160630-5829-472c-b1b0-718097b6fcc4msft-kb4011614-3ba92f3e-451c-45c7-8099-702d514491e8msft-kb4011639-28480f1f-4ec3-4e86-b3ad-443c2d9573efmsft-kb4011639-d7ba089a-fb18-4476-9cd3-6270149d12e4msft-kb4011660-ca0be912-b51d-4878-9028-8f4a5e716a2cmsft-kb4011660-d7594745-04d5-4631-b2d7-289816f4dd43

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.