Excel DDE Field Launching External Command
Dynamic Data Exchange, or DDE, is a legacy Windows mechanism that lets spreadsheet cells pull live values from other applications — a feature attackers have repurposed into a file-based attack technique. A crafted .xlsx or .xlsm workbook embeds a DDE formula such as =cmd|'/c calc'!A1; when the victim opens the file and the formula evaluates, Windows executes the command, and a real attack would swap in PowerShell or an encoded downloader. Because the workbook looks like ordinary spreadsheet content, it can slip past naive filtering. This demo uses a benign DDE formula that only opens Calculator, so it is safe to run. Deep CDR parses and sanitizes the workbook's formulas, strips DDE and other dynamic content, and delivers a reconstructed file that preserves the data while removing the execution trigger.
Attack Technique
DDE formula injection
MITRE ATT&CK
T1559.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗