The risk is extremely high, according to information, for client side & phishing on companies/organizations using a vulnerability that targets Microsoft's most well-known suite, Microsoft Word!!! More specifically, the information states that hackers created a piece of code that allows remote execution of malicious software without the user's knowledge via Microsoft Office.
The vulnerability can be exploited by sending Word RTF (Rich text format) files as attachments (via email or other means). The important thing is that the attack is undetectable by most antiviruses and can be carried out even with the preview function of a malicious email in Outlook (!). It is not necessary to open the attached file, which makes the attack particularly successful against organizations, companies or financial institutions, the majority of whose users use Windows, Office and Outlook!
Microsoft's announcement states:
[box_warning]
Vulnerability in Microsoft Word Could Allow Remote Code Execution
Published:
Version: 1.0
General Information
Executive Summary
Microsoft is aware of a vulnerability affecting supported versions of Microsoft Word. At this time, we are aware of limited, targeted attacks directed at Microsoft Word 2010. The vulnerability could allow remote code execution if a user opens a specially crafted RTF file using an affected version of Microsoft Word, or previews or opens a specially crafted RTF email message in Microsoft Outlook while using Microsoft Word as the email viewer. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights. Applying the Microsoft Fix it solution, “Disable opening RTF content in Microsoft Word,” prevents the exploitation of this issue through Microsoft Word. See the Suggested Actions section of this advisory for more information.
The vulnerability is a remote code execution vulnerability. The issue is caused when Microsoft Word parses specially crafted RTF-formatted data causing system memory to become corrupted in such a way that an attacker could execute arbitrary code. The vulnerability could be exploited through Microsoft Outlook only when using Microsoft Word as the email viewer. Note that by default, Microsoft Word is the email reader in Microsoft Outlook 2007, Microsoft Outlook 2010, and Microsoft Outlook 2013.
On completion of investigation for this vulnerability, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.
We are actively working with partners in our Microsoft Active Protections Program (MAPP) to offer information that they can use to provide additional protections to customers. For information about protections released by MAPP partners, see MAPP Partners with Updated Protections.
Microsoft continues to encourage customers to follow the guidance in the Microsoft Safety & Security Center of enabling a firewall, applying all software updates, and installing antimalware software.
Mitigating Factors:
- An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
- In a web-based attack scenario, an attacker could host a website that contains a webpage that contains a specially crafted RTF file that is used to attempt to exploit this vulnerability. In addition, compromised websites and websites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these websites. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes users to the attacker's website.
Recommendation. Please see the Suggested Actions section of this advisory for more information.
[/box_warning]
The vulnerability mainly targets versions of Microsoft Word 2010, but there are reports that the vulnerability is present and applicable to versions of Microsoft Word 2003, 2007 and even the latest version 2013!! Using the above vulnerability, the hacker-attacker has the ability to remotely manage the computer, extract data and intercept information and passwords without your knowledge! Information, which has not been officially confirmed until now, reports that an additional very important vulnerability has been identified in versions of Sharepoint Portal, the well-known intra-company collaboration platform!
No applicable fix has yet been announced by Microsoft regarding the versions of Microsoft Office that have been placed at IMMEDIATE risk.
[box_info]
In case you wish to protect your computer/terminal as a home user, you can apply the Fix-up that allows disabling RTF in Microsoft Word, until an official update is released.
In a corporate environment, we recommend that system administrators apply Group Policy using Active Directory to all endpoints in bulk, so that you do not have to apply the Fix-up manually. You can read more about this [here]
[/box_info]
We estimate that the security departments of businesses, banks and services should increase their security measures to the maximum in the coming days, since spear phishing attacks in this way have increased worldwide with the aim of installing Malware and intercepting confidential intra-company data. In addition, security departments should be vigilant and inform all users internally about “strange e-mails” with word document attachments that may be received. As a user, it would be a good idea to IMMEDIATELY inform the security managers or the IT department of the company/organization you work for if you receive a strange attachment in Word format!



