Skip to main content
← Back to Demos
Macro advanced · 15 min

Remote Template Injection in DOCX Documents

External template injection abuses a legitimate Word feature: a .docx can reference a remote .dotm template, so macros never appear in the document itself and pass static scans. When the file is opened, Word silently fetches the template, and the attacker-controlled VBA in that template runs with the user's privileges. In this demo, the remote template contains benign VBA that only opens Calculator, mirroring the delivery chain used in real phishing campaigns. Deep CDR removes the template relationship entirely, rebuilding the DOCX so no external fetch is possible. The sanitized document remains fully usable for reading and editing, while the remote-code path that attackers rely on is eliminated.

Attack Technique

External template injection

MITRE ATT&CK

T1221 ↗

Platforms

linuxwindows

File Types

.docx

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---