Vulnerability & Exploit Database

Back to search

Microsoft ADV170021: Microsoft Office Defense in Depth Update

Severity CVSS Published Added Modified
4 (AV:L/AC:M/Au:N/C:P/I:P/A:P) December 12, 2017 December 12, 2017 June 04, 2018

Description

Microsoft has released an update for Microsoft Office that provides enhanced security as a defense-in-depth measure. The update disables the Dynamic Update Exchange protocol (DDE) in all supported editions of Microsoft Word. Microsoft is continuing to investigate this issue and will update this advisory as further updates become available. If you are unable to install the update, or if you need to disable the DDE protocol in other Office applications such as Excel, see Microsoft Security Advisory 4053440. Note that the mitigations listed in the advisory will not disable DDE, but will disable auto-update for any linked fields, including DDE. If you need to change DDE functionality in Word after installing the update, follow these steps: In the Registry Editor navigate to \HKEY_CURRENT_USER\Software\Microsoft\Office\version\Word\Security AllowDDE(DWORD) Set the DWORD value based on your requirements as follows: AllowDDE(DWORD) = 0: To disable DDE. This is the default setting after you install the update. AllowDDE(DWORD) = 1: To allow DDE requests to an already running program, but prevent DDE requests that require another executable program to be launched. AllowDDE(DWORD) = 2: To fully allow DDE requests.

Scan For This Vulnerability

Use our top-rated tool to discover, prioritize, and remediate your vulnerabilities

 Free InsightVM Trial

References

Solution Reference

Microsoft Security Update Guide

Solution

msft-kb4011575-9668caee-bd92-4812-b121-0300a48d5492