b374k
v10
today : | at : | safemode : ON
> / home / facebook / twitter / exit /
name author perms com modified label

Major Zero-Day Flaw in Microsoft Word Asylum rwxr-xr-x 0 5:23 PM

Filename Major Zero-Day Flaw in Microsoft Word
Permission rw-r--r--
Author Asylum
Date and Time 5:23 PM
Label
Action
(pc-Google Images)
McAfee security researchers are warning of a new zero-day vulnerability in Microsoft Word being exploited via attached .rtf files since at least January.

The vulnerability is triggered when a victim opens a trick Word document, which downloads a malicious HTML application from a server, disguised to look like a Rich Text document file as a decoy. The HTML application meanwhile downloads and runs a malicious script that can be used to stealthily install malware.

Researchers at McAfee said because the HTML application is executable, the attacker can run code on the affected computer while evading memory-based mitigations designed to prevent these kinds of attacks.

Security firm FireEye also noted similar malicious .rtf files in its own alert. Both firms say the flaws are within Microsoft's Object Linking and Embedding (OLE) technology and affects all versions of Office, including Office 2016 for Windows 10.

Once you double click the rtf file and the hta executes, at that point, the attacker will have full access to the victim's machine.


via E Hacking News - Latest Hacker News and IT Security News Major Zero-Day Flaw in Microsoft Word http://ift.tt/2oTgFt2

0 comments:

Post a Comment

 

Jayalah Indonesiaku © 2010 Hacker News
VB (Vio b374k) Template design by p4r46hcyb3rn3t