An external program action is a document feature that can launch a command or application when a user interacts with a link or object. In malicious Office files, it can replace macros as the execution trigger and hand control to the operating system through a trusted file format.
What External Program Action Is
An external program action is a document feature that can launch a command or application when a user interacts with a link or object. In malicious Office files, it can replace macros as the execution trigger and hand control to the operating system through a trusted file format.
How External Program Action Works
External program action sits at the boundary between a document viewer and the host operating system. Instead of executing embedded script logic inside the document itself, the document contains an action that tells the application to open a URI, start a local program, or invoke another handler when the object is activated.
That matters because the security decision shifts from “is this document macro-enabled?” to “what will the client do with this action?” The feature is only useful to an attacker if the surrounding application honours the action and the user interaction reaches the triggering object.
Why It Is Used in Malicious Documents
Attackers use this mechanism because trusted document formats often receive less suspicion than executable files. A malicious file can appear to be a normal attachment while still causing code or command execution through an external handler once opened or clicked.
Compared with macro-based delivery, an external program action can reduce reliance on explicit macro prompts or macro settings. That makes it attractive in social engineering chains where the payload is staged after a first user action rather than immediately embedded as visible script.
Security Implications for Document Handling
The main security concern is that a document becomes a launch vector, not just a container for content. That creates a path from content rendering to command execution, which can lead to malware download, credential theft, persistence, or further exploitation if the launched program inherits the user’s trust context.
Defenders should treat such documents as active content with execution potential and not merely as passive files. The control problem is the trust boundary between document parsing, protocol handling, shell execution, and the user’s expectation that opening a file is safe.
Risk and Threat Considerations
External program action is risky because it can bypass macro-focused controls and still produce code execution through a trusted application flow. The threat is strongest when users open untrusted Office files, because the malicious action can move the attack from document content into the operating system.
Failure mechanism: A document viewer or office application resolves the action to a local command, URI handler, or external program, and the user interaction supplies the trigger.
Impact: The attacker can reach execution, staging, or follow-on payload delivery without relying on traditional macros, increasing the chance of compromise from a seemingly ordinary document.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while OWASP ASVS and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP ASVS | V15 — Secure Coding and Architecture | Covers unsafe document-to-execution trust boundaries in application behavior |
| Recommendation — Design document handlers to prevent external actions from reaching arbitrary execution paths. | ||
| NIST SP 800-53 Rev 5 | SI-3 — Malicious Code Protection | Addresses blocking or detecting malicious content that triggers execution |
| AC-3 — Access Enforcement | Relevant where document actions depend on enforced execution and handler restrictions | |
| Recommendation — Inspect incoming documents for action-based payloads before allowing user access. Restrict which handlers and programs document actions may invoke. | ||
| MITRE ATT&CK | T1204 — User Execution | Covers attacks that rely on a victim activating content to trigger execution |
| Recommendation — Map document-click events to T1204 and hunt for execution following user interaction. | ||
Practitioner Guidance
What to watch for: Treat documents that contain external action behavior as suspicious even when they do not contain macros. Security review should focus on whether the file can launch external handlers, how the client application resolves those handlers, and whether user interaction is enough to execute them.
Practitioner takeaway: For document security, the important question is not only “does it have macros?” but also “can it hand control to something outside the document sandbox?”
Related resources from NHI Mgmt Group
- How do organisations know their external risk management program is actually working?
- What breaks when external attack surface management is missing from a security program?
- What are the signs that external exposure is being undercounted in a security program?
- What are the signs that a cybersecurity compliance program is failing before an external audit?