Office DDE attack works in Outlook too – here’s what to do


In the last two weeks, Sophos researchers have kept an eye on a vulnerability in Microsoft’s Dynamic Data Exchange (DDE) protocol used to send messages and share data between applications. Yesterday, new developments revealed an additional dimension to this attack.

