Microsoft Warns of Fresh Email Spam Campaign Exploiting Old Office Vulnerability

It's an old, yet reliable exploit targeted at European users right now.

Advertisement
By Harpreet Singh | Updated: 10 June 2019 16:43 IST
Highlights
  • Hackers are again exploiting an old Office vulnerability, says Microsoft
  • The malicious file can infect a user's system when they just open a file
  • Microsoft is asking users to update their systems, if they haven't

Photo Credit: Twitter/ Microsoft

Microsoft issued a warning on Friday regarding a spam campaign that seems to abuse a security vulnerability in its productivity suite - Office. The campaign involves sending malicious documents that can infect users when they simply open the attached RTF document. As of now, the spam campaign is targeting European users. Microsoft's Security Intelligence account made the announcement in a series of tweets on Friday afternoon.

According to Microsoft's security researchers, the ongoing spam campaign includes RTF documents that exploit the Microsoft Office and Wordpad CVE-2017-11882 vulnerability. Users can be infected by simply opening the attached document.

 

 

Advertisement

The CVE-2017-11882 vulnerability enables RTF and Word documents to execute commands right when they're opened. The vulnerability was patched back in 2017, but Microsoft claims the company still sees the exploit being used in spam campaigns which have increased in the last several weeks. Microsoft is recommending users to apply security updates.

Advertisement

Microsoft said that when a user opens an infected attachment, the file will try to execute a number of scripts written in VBScript, PowerShell, PHP, and others to download the 'payload'. These scripts are generally downloaded from a Pastebin repository.

According to Microsoft, the 'payload' that's download on an infected user's system is an executable backdoor trojan, programmed to connect to a malicious domain. Microsoft is asking all Windows users to install the security update for this vulnerability as soon as possible.

Advertisement

The malicious domain has been taken down, but Microsoft says there's always a possible risk of future campaigns that may use a similar tactic to exploit the vulnerability.

In case you've already applied the November 2017 patch, you're already protected from this vulnerability. This exploit has been used several times, in an effort to target users who may have forgotten to install the software update.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Microsoft, Microsoft Office, Security
Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  4. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  5. Airtel Discontinues These Prepaid Recharge Packs in India
  6. Nothing Phone 3a Lite Goes on Sale in India at This Price
  7. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  8. Here's What India Searched For the Most on Google in 2025
  9. Vivo S50 Colour Options, Key Features Surface Online Ahead of Launch
  10. Motorola Edge 70 Will Launch in India Soon via This E-Commerce Platform
  1. OpenAI, Jony Ive Lose Appeal on ‘io’ Brand as Court Upholds Decision
  2. Dhoolpet Police Station OTT Release Details: When, Where to Watch Tamil-Language Crime Thriller Online?
  3. Netflix to Buy Warner Bros. in $72 Billion Cash, Stock Deal
  4. George Clooney-Starrer Jay Kelly Now Streaming on Netflix: All You Need to Know
  5. Google's Year in Search 2025 Reveals Gemini 3, Nano Banana Pro and Other AI Search Features Launched in India 2025
  6. Poco C85 5G Display Specifications Confirmed Days Ahead of Launch in India: See Expected Specifications
  7. Polar Loop Screen-Free Fitness Tracker Launched in India With Up to Eight Days of Battery Life: Price, Specifications
  8. Xiaomi 17S Pro Said to Be in Development, Could Launch After Xiaomi 17 Ultra Debuts
  9. Motorola Edge 70 India Launch Teased; Flipkart Availability Confirmed: Expected Specifications, Features
  10. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.