Join our Newsletter — 33% off our NHI Course
Home› Glossary› Cyber Security› External Program Action
Cyber Security

External Program Action

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Cyber Security

An external program action is a document feature that can launch a command or application when a user interacts with a link or object. In malicious Office files, it can replace macros as the execution trigger and hand control to the operating system through a trusted file format.

What External Program Action Is

An external program action is a document feature that can launch a command or application when a user interacts with a link or object. In malicious Office files, it can replace macros as the execution trigger and hand control to the operating system through a trusted file format.

How External Program Action Works

External program action sits at the boundary between a document viewer and the host operating system. Instead of executing embedded script logic inside the document itself, the document contains an action that tells the application to open a URI, start a local program, or invoke another handler when the object is activated.

That matters because the security decision shifts from “is this document macro-enabled?” to “what will the client do with this action?” The feature is only useful to an attacker if the surrounding application honours the action and the user interaction reaches the triggering object.

Why It Is Used in Malicious Documents

Attackers use this mechanism because trusted document formats often receive less suspicion than executable files. A malicious file can appear to be a normal attachment while still causing code or command execution through an external handler once opened or clicked.

Compared with macro-based delivery, an external program action can reduce reliance on explicit macro prompts or macro settings. That makes it attractive in social engineering chains where the payload is staged after a first user action rather than immediately embedded as visible script.

Security Implications for Document Handling

The main security concern is that a document becomes a launch vector, not just a container for content. That creates a path from content rendering to command execution, which can lead to malware download, credential theft, persistence, or further exploitation if the launched program inherits the user’s trust context.

Defenders should treat such documents as active content with execution potential and not merely as passive files. The control problem is the trust boundary between document parsing, protocol handling, shell execution, and the user’s expectation that opening a file is safe.

Risk and Threat Considerations

External program action is risky because it can bypass macro-focused controls and still produce code execution through a trusted application flow. The threat is strongest when users open untrusted Office files, because the malicious action can move the attack from document content into the operating system.

Failure mechanism: A document viewer or office application resolves the action to a local command, URI handler, or external program, and the user interaction supplies the trigger.

Impact: The attacker can reach execution, staging, or follow-on payload delivery without relying on traditional macros, increasing the chance of compromise from a seemingly ordinary document.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while OWASP ASVS and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP ASVSV15 — Secure Coding and ArchitectureCovers unsafe document-to-execution trust boundaries in application behavior
Recommendation — Design document handlers to prevent external actions from reaching arbitrary execution paths.
NIST SP 800-53 Rev 5SI-3 — Malicious Code ProtectionAddresses blocking or detecting malicious content that triggers execution
AC-3 — Access EnforcementRelevant where document actions depend on enforced execution and handler restrictions
Recommendation — Inspect incoming documents for action-based payloads before allowing user access. Restrict which handlers and programs document actions may invoke.
MITRE ATT&CKT1204 — User ExecutionCovers attacks that rely on a victim activating content to trigger execution
Recommendation — Map document-click events to T1204 and hunt for execution following user interaction.

Practitioner Guidance

What to watch for: Treat documents that contain external action behavior as suspicious even when they do not contain macros. Security review should focus on whether the file can launch external handlers, how the client application resolves those handlers, and whether user interaction is enough to execute them.

Practitioner takeaway: For document security, the important question is not only “does it have macros?” but also “can it hand control to something outside the document sandbox?”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org