Mastodon Mastodon Mastodon Mastodon

Object Linking and Embedding [OLE]

Updated: · CyberSecureFox Editorial Team

Object Linking and Embedding (OLE) is a Microsoft technology that lets documents contain live objects from other applications, such as an Excel table in Word.

How OLE works

OLE was introduced in 1990 and is built on Microsoft’s Component Object Model (COM). An object can be added to a document in two ways:

  • Linking – the document stores a reference to an external file; changes in the source appear in the document.
  • Embedding – the object’s data is stored inside the document; double-clicking opens it in the original program.

Office files, RTF documents and OneNote notebooks can all contain OLE objects, and the same “compound file” format is used inside older .doc and .xls files.

Why OLE matters for security

Because OLE objects can load other programs and remote content, they have been one of the most abused features in Office for years:

  • CVE-2017-0199 – an RTF or Word file downloaded and ran a remote HTA script through an OLE link;
  • CVE-2017-11882 – a memory corruption bug in the old Equation Editor object, still used in phishing campaigns years after the patch;
  • Follina (CVE-2022-30190) – a document loaded remote HTML that launched the Microsoft Support Diagnostic Tool to run commands;
  • in 2023, after Microsoft blocked internet macros, attackers switched to embedded files in OneNote notebooks.

How to protect yourself

  • Install Office security updates promptly and remove unsupported Office versions.
  • Keep Protected View enabled for files from the internet and e-mail.
  • In companies, use Attack Surface Reduction rules that stop Office from creating child processes.
  • Do not double-click embedded objects or icons in documents from unknown senders.