News by Xiaomi Miui Hellas
Home » All the news » Apps / Roms » Microsoft Office: Researchers Reveal Zero-Day "Follina" Vulnerability
Apps / Roms

Microsoft Office: Researchers Reveal Zero-Day "Follina" Vulnerability

zero-day-tiny-logo

Researchers have publicly revealed one zero-day vulnerability in Microsoft Office which can be exploited using its malicious documents Word resulting in malicious code being executed on the victim's system


Η vulnerability was first discovered by the user @nao_sec on Twitter on May 27th and as mentioned in a post he made at Twitter

The document uses the remote Word template feature to retrieve a file HTML from a remote web server, who in turn uses the shape ms-msdt MSProtocol URI to load code and execute one PowerShell. This should not be possible

Ο Beaumont states that attackers can take advantage of this vulnerability, which he has named "Follina”, Even if the Office macros are off. The Office 2013, 2016, 2019, 2021 and some versions of Office offered through Microsoft 365 are so vulnerable to Windows 10 as well as Windows 11.

Chief Executive Officer Huntress labs, Kyle Hanslovan, showed us how to do this using a Rich Text File to exploit this vulnerability in the preview window in File Explorer Windows 11:

All of this means that this vulnerability allows code to be executed with a single click, (or simply by previewing the malicious document) using support tools (ms-msdt) and system administration tools (PowerShell) that are pre-installed on Windows.

Ο @crazyman_army Reported on Twitter that this vulnerability became known to Microsoft on April 12, but on April 21 it allegedly decided that no security issues were raised.

Ο Beaumont says that "Microsoft may have attempted to fix or mistakenly fix this in Office 365 Insider without documenting or citing a CVE", Sometime in May.

That's it Huntress labs says that he expects "attempts at exploitation via email”And notes that users“should be especially careful about opening attachments", While Microsoft, antivirus companies and the rest of the security community are responding to this threat.

Η Microsoft did not respond immediately to his request PCMag for comment on the subject.


Mi TeamDo not forget to follow it Xiaomi-miui.gr on Google News to be informed immediately about all our new articles! You can also if you use RSS reader, add our page to your list by simply following this link >> https://news.xiaomi-miui.gr/feed/gn

 

Follow us on Telegram  so that you are the first to learn our every news!

 

Follow us on Telegram (English language) so that you are the first to learn our every news!

Read also

Leave a comment

* By using this form you agree to the storage and distribution of your messages on our page.

This site uses Akismet to reduce spam comments. Find out how your feedback data is processed.

Leave a Review

Xiaomi Miui Hellas
The official community of Xiaomi and MIUI in Greece.
Read also
Sony unveils free PS Plus subscription games for…