Image via ID 69434098 © Dennizn | Dreamstime.com
Microsoft has announced that a new cyberattack has been targeting Windows users, with hackers exploiting a security flaw through Office documents.
In an update released by the company this week, the tech giant said it was investigating a remote code execution vulnerability in MSHTML, which works through maliciously-crafted Office documents.
“MSHTML is a component used by myriad applications on Windows. If you’ve ever opened an application that seemingly ‘magically’ knows your proxy settings, that’s likely because it uses MSHTML under the hood,” said Jake Williams, co-founder of incident response company BreachQuest.
With this loophole, hackers can create a dangerous ActiveX control in an Office document that hosts the browser’s engine. Once the user opens the hacked document, usually sent via email, an attacker could gain control of the entire computer.
According to TechRepublic, the exploit affects all versions of Windows, including Windows 7, 8.1, and 10, as well as Windows Server 2008, 2012, 2016, 2019, and 2022. Currently, Microsoft has yet to release a patch to address this problem.
The company said that after it completes the investigation, it will release an update together with its monthly cycle, or roll it out in a special one-time issue. As of now, users can make use of Microsoft Defender Antivirus and Microsoft Defender for Endpoint to ensure they aren’t susceptible to the attack.
In the meantime, users can open Microsoft Office documents in Protected View or Application Guard format, which would prevent the exploit. To enable this function, select the ‘File’ menu in an Office application, followed by ‘Options’.
Within the ‘Options’ window, click on ‘Trust Center’, and then the button for ‘Trust Center Settings’. Finally, select ‘Protected View’ to enable it.
“The good news is that this vulnerability is client-side and requires user interaction. A patch will be available soon. Unfortunately that’s the end of the good news,” said Casey Ellis, founder of cybersecurity platform Bugcrowd.
Ellis said it’s rather easy to access the exploit, which could mean that more attackers are looking to take advantage of it. And should it get worse, the loophole could be used in various attacks, such as ransomware.
Hopefully, Microsoft will be able to release a patch to solve the issue soon enough.
[via
TechRepublic, cover image via
ID 69434098 © Dennizn | Dreamstime.com]