Remote Template Injection in DOCX Documents
External template injection abuses a legitimate Word feature: a .docx can reference a remote .dotm template, so macros never appear in the document itself and pass static scans. When the file is opened, Word silently fetches the template, and the attacker-controlled VBA in that template runs with the user's privileges. In this demo, the remote template contains benign VBA that only opens Calculator, mirroring the delivery chain used in real phishing campaigns. Deep CDR removes the template relationship entirely, rebuilding the DOCX so no external fetch is possible. The sanitized document remains fully usable for reading and editing, while the remote-code path that attackers rely on is eliminated.
Attack Technique
External template injection
MITRE ATT&CK
T1221 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗