2.11.8.7.2.6 Ensure 'Dynamic Data Exchange' is set to 'Disabled'

Information

This policy setting controls the ability to use Dynamic Data Exchange (DDE) in Word.

The recommended state for this setting is: Disabled.

Rationale:

In an email attack scenario, an attacker could leverage the DDE protocol by sending a specially crafted file to the user and then convincing the user to open the file, typically by way of an enticement in an email. The attacker would have to convince the user to disable Protected Mode and click through one or more additional prompts. Email attachments are a primary method an attacker could use to spread malware.

For more information, see Microsoft Security Advisory 4053440 link in the references of this recommendation.

Impact:

None - DDE is disabled by default in Word. Enforcing this policy ensures users cannot enter an unsecure state.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled.

User Configuration\Administrative Templates\Microsoft Word 2016\Word Options\Security\Trust Center\Dynamic Data Exchange

Default Value:

Disabled. (DDE is Disabled.)

See Also

https://workbench.cisecurity.org/benchmarks/12129

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: ce39fd4026581d94538e6248c925f18e23df6743fc717933bf9d3752e7f4e506