HomeSecurityBe careful with the Office documents you open until Tuesday

Be careful with the Office documents you open until Tuesday

McAfee researchers have discovered a previously unknown vulnerability in Microsoft Word (an Office application) that can be used to install different types of malware even on fully updated computers.

Unlike most Office vulnerabilities, this zero-day bug (which has not yet been patched) does not use macros. Macros in Office are a known vulnerability in the application.office

The vulnerability is triggered when a victim opens a malicious Word document, which downloads a malicious HTML application from a server, disguised to look like a Rich Text document. The HTML application downloads and runs a malicious script that can be used to install malware.

McAfee researchers, who first discovered and disclosed the vulnerability on Friday, say that because the HTML application is executable, an attacker can execute code on any computer and can evade memory mitigations designed to prevent such attacks.

McAfee and FireEye (the latter published a similar warning on Saturday) have agreed on the cause of the vulnerability. The issue is related to the Windows Object Linking and Embedding (OLE) feature, which allows an application to link and embed content in other documents, according to the researchers. The Windows OLE feature is used primarily in Office and Windows, is built into WordPad, and has been the cause of several vulnerabilities over the past few years.

Researchers say the flaw can be exploited in all versions of Office, including the latest Office 2016 running on Windows 10, and have been seeing such attacks online since January.

A Microsoft spokesperson confirmed that the company will issue an update for the bug on Tuesday as part of its monthly update rollout.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS