HomeSecurityMicrosoft releases OOB security updates for Office

Microsoft releases OOB security updates for Office

Microsoft has released an out-of-band security update that fixes remote code execution vulnerabilities in an Autodesk FBX library that is embedded in Microsoft Office and Paint 3D applications.

Last month, Autodesk issued security updates for the Autodesk FBX software development kit that resolve remote code execution and denial of service vulnerabilities caused by specially crafted FBX files.

An FBX file is an Autodesk file format used to store 3D models, elements, shapes, and animations.

To exploit these vulnerabilities, an attacker would create a malicious FBX file that would exploit “buffer overflow, type confusion, use-after-free, integer overflow, NULL pointer dereference, and heap overflow vulnerabilities” to perform a DoS attack or remotely execute code.

Office

Microsoft Office uses the Autodesk FBX library

As Microsoft Office 2016, Microsoft 2019, Office 365, and Paint 3D applications use the Autodesk FBX library, Microsoft today released new security updates that resolve these remote code execution and DoS vulnerabilities in their products.

In an advisory titled “ADV200004 | Updates Available for Microsoft Software That Uses the Autodesk FBX Library,” Microsoft explains that opening malicious FBX files in Office applications could lead to remote code execution.

Microsoft is announcing the release of updates to address multiple vulnerabilities found in the Autodesk FBX library, which is embedded in some Microsoft applications. Details about the vulnerabilities can be found here.

Remote code execution vulnerabilities exist in Microsoft products that use the FBX library when processing specially crafted 3D content. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who are running with administrator rights.

To exploit the vulnerabilities, an attacker must send a specially crafted file containing 3D to a user and convince them to open it.

Security updates address these vulnerabilities by correcting the way 3D content is handled by Microsoft software.

How to install Microsoft Office security updates

To install these security updates, Office users can open an Office, click the File menu option, and then select Account.

When the account page opens, on the right, you'll see a section titled “Office Updates” with a button labeled “Update Options.” Click this button and select Update Now.

Microsoft Office will check for and install any available updates.

Once the updates are downloaded and installed, Microsoft Office will need to restart your Office applications. Be sure to save any open documents before doing this.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS