Monday 10 April 2017

Hackers are attacking Word users with new Microsoft Office zero-day vulnerability

By Zack Whittaker

The bug affects all supported versions of Microsoft Word, but will be fixed this week. Attackers are exploiting a previously undisclosed vulnerability in Microsoft Word, which security researchers say can be used to quietly install different kinds of malware — even on fully-patched computers. Unlike most document-related vulnerabilities, this zero-day bug that has yet to be patched doesn’t rely on macros — in which Office typically warns users of risks when opening macro-enabled files. Instead, the vulnerability is triggered when a victim opens a trick Word document, which downloads a malicious HTML application from a server, disguised to look like a Rich Text document file as a decoy. The HTML application meanwhile downloads and runs a malicious script that can be used to stealthily install malware.

http://www.zdnet.com/article/hackers-are-attacking-word-users-with-new-microsoft-office-zero-day-vulnerability/

Share on Facebook

from Educational Technology http://people.uis.edu/rschr1/et/?p=26226

No comments:

Post a Comment