Skip to main content

Unpatched For Years, MS Word Zero-Day Attacks Even If Your Windows Is Fully Updated


MS Office zero-day main1
An unpatched 0-day bug affects all the versions of MS Office and Windows, including Office 2016 running on Windows 10. An attacker can make a user download malicious word file as an email attachment, execute codes, and install malware on victim’s system. Microsoft is currently working on an official fix for the vulnerability.

Researchers at McAfee and FireEye have disclosed another case of email-based hacking methods which can be used to compromise a fully updated and patched Windows operating system, even Windows 10.
The attack vector lies in the form of an unpatched zero-day bug present in all the running versions of Microsoft Office. The root cause lies in an important Office feature known as Object Linking and Embedding (OLE). It allows applications to embed and link to documents and objects.
According to the researchers, a victim opening a suspicious Word file – embedded with an OLE2link object – in an email would trigger winword.exe to initiate an HTTP request to the attacker’s remote server. This results in the download of a malicious .hta file (HTML Application executable) on the victim’s machine. To the user, the HTA file appears as a Microsoft Rich text document with a .doc extension. It also conceals the file from anti-virus software on the machine.
Microsoft Office zero day1
Image: A part of the communication captured by the McAfee researchers
The HTA file runs malicious scripts to terminate winword.exe, which is done to hide the “user prompts generated by the OLE2link.” The exploit shows some bait Word document to the user while it’s busy downloading extra payload in the background.
The zero-day attack disclosed by the researchers affects all the versions of Microsoft Windows and MS Office. However, Microsoft is aware of the vulnerability and we can expect a patch in the near future.

Meanwhile, you can use countermeasures

The Protected View feature built into Microsoft Office makes the attack vector ineffective. You can use it to open attachments until Microsoft releases security fixes. Also, you should refrain yourself from obtaining Office files from untrusted locations.
If you have something to add, drop your thoughts and feedback.

Comments

Follow Us

WHAT'S HOT

How To Speed Up Windows Using ReadyBoost And USB Drive? Does It Still Work?

In Microsoft Windows, ReadyBoost is a software feature that speeds up the system by storing application files and data as cache in a USB drive. This is beneficial in case the system is running a slow hard drive. The ReadyBoost works with USB drives, SD cards, and CF cards. However, it may not be able to deliver considerable performance in the

How To Install Ubuntu MATE For The Raspberry Pi 2 and Raspberry Pi 3

Ubuntu MATE:  We have done what we can to optimise the build for the Raspberry Pi 2 and Raspberry Pi 3, you can comfortably use applications such as LibreOffice and Firefox. But the microSDHC I/O throughput is a bottleneck so  we  highly  recommend that you use a Class 6 or Class 10 microSDHC  card.  Ubuntu MATE 16.04 also fully supports the built-in Bluetooth and Wifi on

Which Is The Best Operating System For Gaming Among SteamOS , Ubuntu And Windows 10

Years ago, MS-DOS was the ‘go to’ operating system when you wanted to engage in prolonged gaming sessions but its complexity required that a better alternative should be provided to the masses that will also feature a unique interface for easy use. After years of

Windows Subsystem For Linux Is Beta No More, Gets “Full Support” In Windows 10 Fall Creators Update

As we told you earlier, WSL on Windows 10  moved out of beta  in August. It still carries the beta tag in Windows 10 Creators Update. Also, it won’t require people to enable developer