I first wrote about the Word {DDEAUTO} field and its weird ways in “Hacker’s Guide to Word for Windows.” Yes, that was 23 years ago. {DDEAUTO} precede
[See the full post at: Microsoft releases a Security Advisory about the DDEAUTO fandango]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Microsoft releases a Security Advisory about the DDEAUTO fandango
Home » Forums » Newsletter and Homepage topics » Microsoft releases a Security Advisory about the DDEAUTO fandango
- This topic has 12 replies, 9 voices, and was last updated 5 years, 4 months ago.
AuthorTopicwoody
ManagerViewing 4 reply threadsAuthorReplies-
Purg2
AskWoody LoungerIt would seem that I have a version of Office that isn’t covered by this security advisory.
Office Starter v14 (Excel & Word only)
See image 01 of my image gallery.
https://imgur.com/a/JftRQImage 02 shows that the trust center settings are missing.
Image 03 shows that the registry key is also missing.
A few days ago I had unchecked the box in options that says “update automatic links at open.” However, it’s still a bit unclear methinks.
This leads me to believe that the starter version of office is either not affected or could still be vulnerable due to the lack of security settings.
Maybe DDEAUTO only applies to enterprise or some other version that is not for home, scratches head.
Win 8.1 (home & pro) Group B, Linux Dabbler
1 user thanked author for this post.
-
woody
ManagerWord Starter 2010 doesn’t support many of the fields that are in the “real” Word.
See https://support.office.com/en-us/article/Word-features-that-are-not-fully-supported-in-Word-Starter-8467554a-e9d6-4404-a599-f036b29deed8 for details.
It isn’t clear to me if this means {DDEAUTO} fields in existing documents will fire when opened in Word Starter.
1 user thanked author for this post.
-
alpha128
AskWoody PlusI disabled DDEAUTO in Word, on both my work and home machines, by following Martin Brinkmann’s steps. There were no apparent ill effects.
I did disable DDEAUTO in Excel, but I re-enabled it right after I discovered that you can’t launch Excel files from Windows Explorer without this turned on.
1 user thanked author for this post.
-
Noel Carboni
AskWoody_MVPI did disable DDEAUTO in Excel, but I re-enabled it right after I discovered that you can’t launch Excel files from Windows Explorer without this turned on.
I’ve found that you CAN do that IF you also reconfigure the command lines that start Excel as a result of double-clicking a .xls file in Explorer. For me, with Office 2010, this also restores the ability to have spreadsheets in totally separate windows – i.e., just like in the good ol’ days when Windows really did windows. For me, with multiple monitors, I find this a necessity.
Windows Update reverts this functionality, though, whenever an Office update is applied, so I reapply the following registry file every time after an update. Note that I strongly recommend researching and UNDERSTANDING what this does before applying it. Note that this is specific to Office 2010!
Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\Excel.CSV\shell\Edit\command] @="\"C:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE\" /e \"%1\"" "command"=- [HKEY_CLASSES_ROOT\Excel.CSV\shell\Open\command] @="\"C:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE\" /e \"%1\"" "command"=- [-HKEY_CLASSES_ROOT\Excel.CSV\shell\Open\ddeexec] [HKEY_CLASSES_ROOT\Excel.Sheet.8\shell\Edit\command] @="\"C:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE\" /e \"%1\"" "command"=- [HKEY_CLASSES_ROOT\Excel.Sheet.8\shell\Open\command] @="\"C:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE\" /e \"%1\"" "command"=- [-HKEY_CLASSES_ROOT\Excel.Sheet.8\shell\Open\ddeexec] [HKEY_CLASSES_ROOT\Excel.Sheet.12\shell\Edit\command] @="\"C:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE\" /e \"%1\"" "command"=- [HKEY_CLASSES_ROOT\Excel.Sheet.12\shell\Open\command] @="\"C:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE\" /e \"%1\"" "command"=- [-HKEY_CLASSES_ROOT\Excel.Sheet.12\shell\Open\ddeexec] [HKEY_CLASSES_ROOT\Excel.OpenDocumentSpreadsheet.12\shell\Edit\command] @="\"C:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE\" /e \"%1\"" "command"=- [HKEY_CLASSES_ROOT\Word.Document.8\shell\Open\command] @="\"C:\\Program Files\\Microsoft Office\\Office14\\WINWORD.EXE\" /n \"%1\"" "command"=- [HKEY_CLASSES_ROOT\Word.Document.12\shell\Open\command] @="\"C:\\Program Files\\Microsoft Office\\Office14\\WINWORD.EXE\" /n \"%1\"" "command"=-
-Noel
5 users thanked author for this post.
-
alpha128
AskWoody PlusThanks for the information Noel. But I’m running Office 2013 and either way your approach is more bother than I want to deal with.
Since I normally have libraries disabled, I already feel like I’m playing Russian roulette every time I install a Windows roll-up.
1 user thanked author for this post.
-
AlexEiffel
AskWoody_MVPHeavy Excel users might want to note the following.
I am not sure if it applies to your solution Noel, but when I do open documents in Excel 2010 in separate Windows, copy-past behaves differently and is quite annoying. I have to paste as csv or else I get something that looks more like a picture than a bunch of data. The way I open Excel files in different windows is open one file by double-clicking on it, open Excel (blank), open the second file through the open menu in the newly opened Excel blank file.
For this reason, I only open Excel files in different windows when I really need a side-by-side comparison of both files.
1 user thanked author for this post.
-
MrJimPhelps
AskWoody MVPFor me, with Office 2010, this also restores the ability to have spreadsheets in totally separate windows – i.e., just like in the good ol’ days when Windows really did windows. For me, with multiple monitors, I find this a necessity.
Excel 2016 restores the ability to open spreadsheets in two separate windows. The only caveat is that if your Excel window is maximized, the second spreadsheet will open on top of the first spreadsheet. But the windows aren’t fused together like they are in Excel 2010; you can easily separate them simply by moving one of them to another monitor.
This was my only complaint about Excel 2010.
Group "L" (Linux Mint)
with Windows 8.1 running in a VM1 user thanked author for this post.
-
Noel Carboni
AskWoody_MVPTypical Microsoft. Restore a critical feature or function that an older version had and which was arbitrarily removed (or just made non-default) and call it an incentive to upgrade to the newest version.
They are clearly just managing their old code base into the ground. I guess they just want to get out of the software business, presumably because they’re doing so well making hardware. LOL
-Noel
-
-
anonymous
GuestPerhaps worth noting that there exist 3rd party micropatches for Office that completely eliminate the DDE-related threat, even if attacker tricks the user to manually update a DDE field: https://0patch.blogspot.com/2017/10/0patching-office-dde-ddeauto.html
Honeyko
AskWoody LoungerIn my opinion you ought to go to Defcon 1, as 1709 is still a BSOD-generator three weeks after roll-out. I have an external USB “legacy” (MBR) drive that I keep in order to have a “master” external for use in troubleshooting systems while on-the-go.
I updated this drive on Nov. 7 after it had been sitting on a shelf for a month (so this was not a case of “old” launch-day updates sitting pending for weeks), and immediately noticed that it would no longer boot some systems (such as an HP Envy laptop) while having no issues with others (an HP Pavilion mini-tower of the same vintage). Weirdly, a clone of the drive to the laptop’s internal drive resulted in the OS working, but it refuses to boot externally. (This is not a drive or cabling issue.)
Interestingly, 1703 did not appear to be problematic, as least insofar as external booting went.
Edit to remove HTML
1 user thanked author for this post.
NetDef
AskWoody_MVP-
woody
Manager
Viewing 4 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Another Windows media creation tool? Sure, why not.
by
Alex5723
7 hours, 29 minutes ago -
Microsoft Defender : Legit URLs marked as malicious
by
Alex5723
7 hours, 36 minutes ago -
Refurbished HP ProBook
by
Kathy Stevens
10 hours, 29 minutes ago -
Microsoft PC Manager (beta) updates
by
Alex5723
3 hours ago -
Ubuntu Cinnamon becomes an official flavor, making Linux Mint obsolete
by
Alex5723
14 hours, 23 minutes ago -
HDMI KVM switch for DP
by
freelab23
22 hours, 8 minutes ago -
My Experience with Win 11 ver 22H2
by
agoldhammer
1 day, 4 hours ago -
Email from Mail on my iPhone to Gmail address failed
by
DrRon
2 hours, 31 minutes ago -
Can’t Update Win 10 past 21H2
by
cmndo97
1 day, 6 hours ago -
Revo Uninstaller (freeware) Updates
by
Microfix
23 hours, 8 minutes ago -
The Third deployment phase for CVE-2022-37967 starts April 11, 2023
by
Alex5723
1 day, 7 hours ago -
Firefox to support Windows 7 and 8 systems well into 2024 at least
by
Alex5723
15 hours, 35 minutes ago -
Microsoft 365 Personal – Repeated Free Two Month Extensions
by
BarryEB
6 hours, 17 minutes ago -
KB5023702 for Server 2019 – Defer as of MPL March 27
by
Aviel
14 hours, 37 minutes ago -
eSIM out, iSIM in?
by
Alex5723
1 day, 16 hours ago -
MS-DEFCON 4: Win11 22H2 not ready for prime time
by
Susan Bradley
3 hours, 35 minutes ago -
Email from Mail on my iPhone to Gmail address failed
by
DrRon
1 day, 18 hours ago -
Microsoft Edge Remover
by
Alex5723
1 day, 5 hours ago -
Windows Desktop refreshes repeatedly every few seconds
by
JimT777
14 hours, 4 minutes ago -
Apple zero days fixed today
by
Susan Bradley
1 day, 14 hours ago -
W10 22H2 Desktop rogue icon won’t allow me to rename, delete, or replace it
by
lanshark
5 hours, 10 minutes ago -
Footnote separators not deleting
by
Ursula
2 days, 3 hours ago -
Should I Go Beyond Version 21H2
by
kstephens43
19 hours, 24 minutes ago -
MacStealer: New macOS-based Stealer Malware Identified
by
Alex5723
2 days, 2 hours ago -
PowerShell – Testers Needed
by
RetiredGeek
3 hours, 55 minutes ago -
Audio from www.whenradiowas.com stops playing after 7-20 minutes
by
David Pressman
1 day, 11 hours ago -
KB4023057: Update for Windows Update Service components
by
RetiredGeek
1 day, 6 hours ago -
win 12 as BORG?
by
krism
2 days, 3 hours ago -
Windows 11 — should I stay on Windows 10?
by
DDR
1 day, 6 hours ago -
Did I really install PaintShop Pro?
by
Mike Ray
2 days, 2 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.