Do you use Office? There is a vulnerability in DDE, a feature built into Office applications that is currently being exploited by many to carry out attacks. DDE, or Dynamic Data Exchange, is a feature of Microsoft Office designed to allow applications to exchange data with each other.
You can use DDE, for example, to update a table in a Word document using Excel data.
The protocol is widely used, not only in Microsoft Office applications like Word or Excel, but also through Visual Basic and many others.
What makes the vulnerability particularly worrisome is that it does not require macros. Attacks currently underway use e-mail to distribute malicious Office documents.
Users who open these documents receive warning prompts in Office. Word, for example, displays the warning “This document contains links that may refer to other files. Do you want to update this document with data from the linked files?”
Most security applications do not detect any threats in Office documents.
Of course, you can always protect your data by selecting “no” when Office prompts appear. Below we will see how you can add another layer of protection. This way, you will be able to protect your system regardless of the choices Office users make when encountering such malicious documents.
Obviously, this is only an option if the DDE feature is not required. It should be noted that home users do not lose anything by disabling DDE, but companies may need it and thus may not want to disable the feature completely.
Disable DDE
If you are using Microsoft Word 2016 or Microsoft Excel 2016, select Options > Advanced and uncheck “Update automatic links on open”
In Excel, you should also select “Ignore other applications that use Dynamic Data Exchange (DDE)”.
The settings are located in the following paths:
In Excel, Administrative Templates > Microsoft Excel 2016 > Excel Options > Advanced.
Ask to update automatic connections
Ignore other apps

For Word Administrative Templates > Microsoft Word 2016 > Word Options > Advanced.
Update automatic links on opening
Below we will see how you can do all this with one click... from your computer's Registry:
The file you include in the zip contains the following code:
Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options] "DontUpdateLinks"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Options] "DontUpdateLinks"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options] "DontUpdateLinks"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\WordMail] "DontUpdateLinks"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Options\WordMail] "DontUpdateLinks"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options\WordMail] "DontUpdateLinks"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\OneNote\Options] "DisableEmbeddedFiles"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\OneNote\Options] "DisableEmbeddedFiles"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Options] "DontUpdateLinks"=dword:00000001 "DDEAllowed"=dword:00000000 "DDECleaned"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Excel\Options] "DontUpdateLinks"=dword:00000001 "DDEAllowed"=dword:00000000 "DDECleaned"=dword:00000001 "Options"=dword:00000117 [HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Options] "DontUpdateLinks"=dword:00000001 "DDEAllowed"=dword:00000000 "DDECleaned"=dword:00000001 "Options"=dword:00000117
Open the zip on your computer (e.g. on the desktop) and double-click on the file.
