It creates risk because it turns ordinary document handling into an execution path without relying on macros, which many defenders already watch for. The exploit can work from a normal .docx or .rtf file and can bypass user assumptions about safe previewing. That widens the attack surface and makes initial access easier for attackers targeting Windows endpoints.
Why document-based exploits are especially dangerous for endpoint teams
Document-based exploits are high-risk because they abuse a trust boundary that defenders often treat as routine, file handling. The issue is not just that the file is malicious, it is that the exploit can turn normal user workflow into code execution before traditional macro-based controls or user suspicion have a chance to help. That makes detection, triage, and response harder on Windows endpoints.
What raises the risk is the combination of familiar formats, low-friction delivery, and weak user visibility. A .docx or .rtf file can arrive through email, chat, or a shared drive, then trigger activity that looks like ordinary document processing rather than an obvious exploit chain. Endpoint teams must therefore assume that “safe-looking” file types can still be active attack vectors.
Because the file is the initial object of trust, the exploit compresses the attack timeline. The endpoint may move from open, to process launch, to follow-on payload activity with very little opportunity for a human to notice a suspicious prompt or for a macro policy to block execution. That is why document-based exploitation tends to create disproportionate operational burden for security teams.
What makes the attack path hard to see and contain
The key problem is that document exploits often blend into normal business activity. Security tools may see a document open event, a preview action, or a renderer process start, but not necessarily a clearly malicious action until after execution has already occurred. This is especially problematic when the exploit uses built-in document handling features rather than overt script or macro behavior.
Endpoint controls also face a detection gap when the initial access mechanism is decoupled from the final payload. Teams may focus on common indicators like macro abuse, yet the exploit chain may arrive through rendering, link-handling, or file parsing logic. That means the control that would normally trigger a user warning or policy block may never activate.
For defenders, that changes containment strategy. Once a document can produce execution without the usual signal, triage must look beyond the attachment itself and into child processes, network callbacks, spawned interpreters, and post-exploitation activity. The document is only the entry point, not the whole incident.
What endpoint teams should infer from a Follina-style exploit
Follina is a reminder that endpoint security cannot rely on “macro-free” as a safe condition. Security teams should treat document parsing and previewing as part of the attack surface, not just the file-open action itself. A format that appears benign to users may still be a delivery vehicle for initial execution and downstream compromise.
It also shows why layered controls matter. File-type filtering, attachment sandboxing, process telemetry, exploit protection, and rapid isolation all contribute differently, but none alone is sufficient. The practical lesson is to assume that document-based exploits will exploit the gap between user trust and machine behavior.
Risk and Threat Considerations
Document-based exploits create exposure because they can convert an ordinary attachment into a reliable initial access path, especially where users and tools assume that previewing or opening a document is low risk. Once execution is triggered, the attack can bypass the user’s mental model and move directly into payload delivery or lateral follow-on activity.
Failure mechanism: The exploit abuses document parsing or rendering logic so that malicious code runs without requiring the usual macro pathway or obvious user action, which weakens common endpoint assumptions about safe file handling.
Impact: Attackers gain a more dependable foothold on Windows endpoints, defenders lose some of their most obvious detection cues, and response work shifts from blocking a suspicious attachment to investigating an already-executed intrusion path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SI-3 — Malicious Code Protection | Document exploits can deliver code through trusted files. |
| SI-4 — System Monitoring | Endpoint teams need visibility into document-triggered child processes and callbacks. | |
| CM-7 — Least Functionality | Reducing risky document-handling features shrinks the attack surface. | |
| Recommendation — Inspect document content and block exploit payloads before execution. Correlate document opens with process and network telemetry. Disable unnecessary document features and parsers on endpoints. | ||
| NIST CSF 2.0 | DE.CM-01 — Networks and network services are monitored to detect potential cybersecurity events | Exploit-driven endpoints require behavior monitoring for follow-on activity. |
| Recommendation — Monitor endpoint and network events for suspicious document-triggered activity. | ||
| CIS Controls v8 | CIS-10 — Malware Defenses | Document exploits are a malware delivery problem as well as a file-format problem. |
| Recommendation — Use malware defenses and sandboxing for untrusted documents. | ||
Practitioner Guidance
What to verify: Confirm whether your telemetry can distinguish document open, preview, renderer activity, child-process creation, and network egress. If those events are not correlated, a document exploit can look like routine office activity until after the payload has executed.
Decision rule: If a document type can trigger code execution without macros, treat it as a content-execution risk, not just a file-policy problem. That means isolating untrusted documents, hardening endpoint exploit protection, and prioritising rapid host containment when suspicious child processes appear.
Common mistake: Teams often over-index on macro controls and underinvest in document parsing telemetry. The better question is whether the endpoint can detect abnormal behavior after the file has already been opened, because that is where these attacks tend to evade first-pass controls.
Practitioner takeaway: The risk is not that the document is merely malicious, it is that a trusted workflow can become an execution primitive, so endpoint teams need controls that detect behaviour, not just file type.
Related resources from NHI Mgmt Group
- Why does malware delivered through documents, fake installers, and script-based chains create so much risk for endpoint security teams?
- Why do stripped audit-log fields create so much risk for IAM and cloud security teams?
- Why do browser-based verification flows create security risk for identity teams?
- Why do endpoint-based signing models create so much risk during a post-quantum cryptography transition?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org