Skip to main content
← Back to Demos
Macro beginner · 15 min

Excel DDE Field Launching External Command

Dynamic Data Exchange, or DDE, is a legacy Windows mechanism that lets spreadsheet cells pull live values from other applications — a feature attackers have repurposed into a file-based attack technique. A crafted .xlsx or .xlsm workbook embeds a DDE formula such as =cmd|'/c calc'!A1; when the victim opens the file and the formula evaluates, Windows executes the command, and a real attack would swap in PowerShell or an encoded downloader. Because the workbook looks like ordinary spreadsheet content, it can slip past naive filtering. This demo uses a benign DDE formula that only opens Calculator, so it is safe to run. Deep CDR parses and sanitizes the workbook's formulas, strips DDE and other dynamic content, and delivers a reconstructed file that preserves the data while removing the execution trigger.

Attack Technique

DDE formula injection

MITRE ATT&CK

T1559.002 ↗

Platforms

linuxwindows

File Types

.xlsx

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---