Rapid7 Vulnerability & Exploit Database

Microsoft ADV170021: Microsoft Office Defense in Depth Update

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Microsoft ADV170021: Microsoft Office Defense in Depth Update

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
12/12/2017
Created
07/25/2018
Added
12/12/2017
Modified
06/03/2019

Description

Microsoft has released an update for Microsoft Office that provides enhanced security as a defense-in-depth measure. The update disables the Dynamic Data Exchange protocol (DDE) in all supported editions of Microsoft Word. Microsoft is continuing to investigate this issue and will update this advisory as further updates become available. If you are unable to install the update, or if you need to disable the DDE protocol in other Office applications, see Microsoft Security Advisory 4053440. Note that the mitigations listed in the advisory will not disable DDE, but will disable auto-update for any linked fields, including DDE. If you need to change DDE functionality in Word after installing the update, follow these steps: In the Registry Editor navigate to \HKEY_CURRENT_USER\Software\Microsoft\Office<version>\Word\Security AllowDDE(DWORD) Set the DWORD value based on your requirements as follows: AllowDDE(DWORD) = 0: To disable DDE. This is the default setting after you install the update. AllowDDE(DWORD) = 1: To allow DDE requests to an already running program, but prevent DDE requests that require another executable program to be launched. AllowDDE(DWORD) = 2: To fully allow DDE requests. **Update: ** On 1/9/2018, Microsoft released an update for Microsoft Office that adds defense-in-depth configuration options to selectively disable the DDE protocol in all supported editions of Microsoft Excel. If you need to change DDE functionality in Excel after installing the update, follow these steps: In the Registry Editor navigate to \HKEY_CURRENT_USER\Software\Microsoft\Office<version>\Excel\Security DisableDDEServerLaunch(DWORD) Set the DWORD value based on your requirements as follows: DisableDDEServerLaunch = 0: Keep DDE server launch settings unchanged from their initial behavior. This is the default setting after you install the update. DisableDDEServerLaunch = 1: Do not display the dialog that allows users to choose whether to launch a specific DDE server. Instead, behave automatically as though the user chose the default choice of NO. In the Registry Editor navigate to \HKEY_CURRENT_USER\Software\Microsoft\Office<version>\Excel\Security DisableDDEServerLookup(DWORD) Set the DWORD value based on your requirements as follows: DisableDDEServerLookup = 0: Keep DDE server lookup settings unchanged from their initial behavior. This is the default setting after you install the update. DisableDDEServerLookup = 1: Disable querying for DDE Server availability – no query attempt will be made to find DDE servers. .

Solution(s)

  • msft-kb4011590-bc12ce88-f8f7-4c5b-9b68-e39fb7b58156
  • msft-kb4011590-e71fafa0-9d15-478f-9486-60db31d2325c
  • msft-kb4011602-2b233136-5e49-457a-81f9-f81774776aec
  • msft-kb4011605-c77fd586-bd96-4165-b594-ffbc1272aea1
  • msft-kb4011606-33d03608-2a03-4917-932c-14cbc3d819ee
  • msft-kb4011608-1e5d7289-59aa-43f3-b8ec-d2a9554efbdb
  • msft-kb4011612-8230d598-8ab1-4efc-89b6-d3507a6dfd20
  • msft-kb4011612-8c0e84f3-1d9c-4794-b5e5-639c12f3f87b
  • msft-kb4011614-18160630-5829-472c-b1b0-718097b6fcc4
  • msft-kb4011614-3ba92f3e-451c-45c7-8099-702d514491e8
  • msft-kb4011639-28480f1f-4ec3-4e86-b3ad-443c2d9573ef
  • msft-kb4011639-d7ba089a-fb18-4476-9cd3-6270149d12e4
  • msft-kb4011660-ca0be912-b51d-4878-9028-8f4a5e716a2c
  • msft-kb4011660-d7594745-04d5-4631-b2d7-289816f4dd43

insightVM

Advanced vulnerability management analytics and reporting.
Key Features
  • Lightweight Endpoint Agent
  • Live Dashboards
  • Real Risk Prioritization
  • IT-Integrated Remediation Projects
  • Cloud, Virtual, and Container Assessment
  • Integrated Threat Feeds
  • Easy-to-Use RESTful API
  • Automation-Assisted Patching
  • Automated Containment
Free InsightVM Trial View All Features

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;