Netskope Threat Labs

FILE-OTHER Microsoft Word DDEauto code execution attempt

IPS-SWG

1 SID: 45215

First seen
February 2022
Last seen
October 2026

Detects documents using dynamic data exchange fields to execute commands without macros. Opening the document runs the embedded command through the protocol handler, a technique documented by researchers and used in phishing campaigns to bypass macro defenses.