-
Word’s DDEAUTO field considered harmful
Wow. This one goes all the way back to Hacker’s Guide to Word for Windows — which was published in 1994.
Etienne Stalmans and Saif El-Sherei at Sensepost have publicized the {DDEAUTO} field’s unruly behavior. What they say is true — if you open a Word doc that contains a {DDEAUTO} field, and you click through the warnings, arbitrary code can be executed. That’s as it was designed.
They miss one important point, though. If you open a DOCX that comes from the internet, at least with a bone-stock Word installation, you have to click the “Enable Editing” button before you see the other two warning dialogs.
Everything old is new again….