Cybersecurity researchers have uncovered a flaw in Microsoft Office 2016 and earlier versions that allows a hacker to embed malicious code within a file, tricking users into running the code on their computers.
This was discovered by researchers at Cymulate and essentially the bug takes the “Online Video” option in Word files, a feature that allows users to embed an online video with a link to YouTube. When the user adds the video to a Word file, the online video automatically generates an embedded HTML code, which is executed when the thumbnail within the document is clicked by the viewer. It is considered quite easy to open and edit, since Word Doc (.docx) files can compress media packages and form folders.

According to the researchers, the folder configuration is called “document.xml,” which is a predefined XML file used by Word that contains embedded code for the video and can be edited to replace the current video with iFrame code and any HTML or JavaScript running in the background. In simpler terms, a hacker can exploit the flaw by replacing the real YouTube video with a malicious video, which in turn will be executed by the Internet Explorer Download Manager.
What does the error look like?
To demonstrate the magnitude of the vulnerability, Cymulate researchers created a proof-of-concept that shows what a malicious file with an embedded video looks like when the user clicks on the video thumbnail.
The researchers reported the specific bug affecting all users with MS Office 2016 or earlier, but Microsoft refused to acknowledge it as a vulnerability. The company said the software interprets HTML code as designed and cannot take any action against any attacks using the specific flaw.
However, to maintain file security, Cymulate suggested that users be particularly careful and prohibit access to Word files with the "embeddedHtml" tag embedded in the Document.xml file.
