Beware of the Office documents you open until Tuesday

Her researchers discovered an unknown vulnerability in Microsoft Word (Office application), which can be used to install different kinds of malware even on fully updated computers.

Unlike most Office vulnerabilities, this zero-day bug (not yet repaired) does not use macros. Macros in Office is a known vulnerability of the application.office

Vulnerability is triggered when the victim opens a dumb Word document that downloads a malicious HTML application from a server that is disguised to resemble a Rich Text document. The HTML application downloads and runs a malicious script that can be used to install malware.

McAfee researchers, who first discovered and published vulnerability on Friday, report that because the HTML application is executable, the attacker can run code on each computer and can avoid memory mitigation designed to prevent this attacks.

McAfee and (η τελευταία δημοσίευσε μια παρόμοια προειδοποίηση το Σάββατο) συμφώνησαν για την αιτία της ευπάθειας. Το θέμα σχετίζεται με τη λειτουργία Windows Object Linking and Embedding (OLE), η οποία επιτρέπει σε μια εφαρμογή τη σύνδεση και την ενσωμάτωση περιεχομένου σε άλλα έγγραφα, σύμφωνα με τους ερευνητές. Το χαρακτηριστικό Windows OLE χρησιμοποιείται κυρίως στο Office και τα Windows, είναι ενσωματωμένο στο WordPad, και είναι η αιτία πολλών τρωτών σημείων κατά τη διάρκεια των τελευταίων ετών.

The researchers report that can be exploited in all versions of Office, including the latest Office 2016 running on Windows 10, and have identified such online since January.

A Microsoft spokesman confirmed that will issue an update for the bug on Tuesday as part of its monthly update rollout.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).