Microsofts Office products have been fertile ground for a variety of new attack vectors. DDE (Dynamic Data Exchange) is one of the methods for transferring data between applications. The DDE code injection technique has been extensively covered elsewhere, but it doesnt hurt to recap how it works quickly. When a file is opened, every line of the file is inspected separately. Excel checks if the contents of a line starts with one of its command characters. The expression, when talking about DDE, can roughly be represented as: Command|arguments!cell”]
Source: https://blog.reversinglabs.com/blog/cvs-dde-exploits-and-obfuscation