Don't miss the latest stories
Advertise Newsletter
Network
  • The Creative Finder
  • The Bazaar
  • Deals
  • Status Is Down
Community
  • Sign up / Log in
  • Discussion Forums
  • Calendar of Events
NEW

Follow

Share this

Microsoft
Apps
Cybersecurity
Laptops
Productivity
Technology
  • Laptops
  • Productivity
  • Technology
MENU
  • Advertise with us
  • Submit tip/feedback
  • Work with us
  • Subscribe to newsletter
  • Subscribe to RSS
Advertise here
Advertisement

Microsoft Warns New Cyberattack Could Be Targeting Your Office Documents

By Alexa Heah, 09 Sep 2021

Subscribe to newsletter
Like us on Facebook

Image via ID 69434098 © Dennizn | Dreamstime.com

Microsoft has announced that a new cyberattack has been targeting Windows users, with hackers exploiting a security flaw through Office documents.

In an update released by the company this week, the tech giant said it was investigating a remote code execution vulnerability in MSHTML, which works through maliciously-crafted Office documents.

“MSHTML is a component used by myriad applications on Windows. If you’ve ever opened an application that seemingly ‘magically’ knows your proxy settings, that’s likely because it uses MSHTML under the hood,” said Jake Williams, co-founder of incident response company BreachQuest.

With this loophole, hackers can create a dangerous ActiveX control in an Office document that hosts the browser’s engine. Once the user opens the hacked document, usually sent via email, an attacker could gain control of the entire computer.

According to TechRepublic, the exploit affects all versions of Windows, including Windows 7, 8.1, and 10, as well as Windows Server 2008, 2012, 2016, 2019, and 2022. Currently, Microsoft has yet to release a patch to address this problem.

The company said that after it completes the investigation, it will release an update together with its monthly cycle, or roll it out in a special one-time issue. As of now, users can make use of Microsoft Defender Antivirus and Microsoft Defender for Endpoint to ensure they aren’t susceptible to the attack.

Advertisement
Advertisement


In the meantime, users can open Microsoft Office documents in Protected View or Application Guard format, which would prevent the exploit. To enable this function, select the ‘File’ menu in an Office application, followed by ‘Options’.

Within the ‘Options’ window, click on ‘Trust Center’, and then the button for ‘Trust Center Settings’. Finally, select ‘Protected View’ to enable it.

“The good news is that this vulnerability is client-side and requires user interaction. A patch will be available soon. Unfortunately that’s the end of the good news,” said Casey Ellis, founder of cybersecurity platform Bugcrowd.

Ellis said it’s rather easy to access the exploit, which could mean that more attackers are looking to take advantage of it. And should it get worse, the loophole could be used in various attacks, such as ransomware.

Hopefully, Microsoft will be able to release a patch to solve the issue soon enough.



[via TechRepublic, cover image via ID 69434098 © Dennizn | Dreamstime.com]
Receive interesting stories like this one in your inbox
Advertise here

More related news

Advertise here
Also check out these recent news
Web Design
Link to news page

When Your Website Goes Down, This Is the Page Customers Meet Instead

2027
Link to news page

2027 Already Has A Color Of The Year And It’s Beginning On ‘Grounded’ Territory

IKEA
Link to news page

IKEA & Xbox Press Play On Furniture & Storage Inspired By The Iconic Controller

Fashion
Link to news page

Vogue Presents ‘United Flags of Fashion’ With Top Designers For All 50 States

Coca-Cola
Link to news page

Coca-Cola Pours Fresh Life Into Its Iconic Branding With Worldwide Redesign