Microsoft Word Affected by Critical Office Zero-Day Vulnerability, Reports McAfee

Advertisement
By Ketan Pratap | Updated: 12 April 2017 19:02 IST
Highlights
  • New exploit works on all Microsoft Office versions
  • Microsoft to release fix soon
  • McAfee recommends enabling Office Protected View

Security software company McAfee has discovered a new zero-day vulnerability that affects all versions of Microsoft Word. According to the company, the new zero-day exploit works on all Microsoft Office versions, including the latest Office 2016 running on Windows 10. For those unaware, a zero-day vulnerability or zero-day attack is a threat that can take advantage of a previously unknown susceptibility in an app or Web service that has not been addressed or patched by developers.

McAfee in its research report detailed it discovered the exploit in action in late January. The samples collected by the team saw the exploit organised as Word files (more specially, RTF files with ".doc" extension name).

"The exploit connects to a remote server (controlled by the attacker), downloads a file that contains HTML application content, and executes it as an .hta file. Because .hta is executable, the attacker gains full code execution on the victim's machine. Thus, this is a logical bug, and gives the attackers the power to bypass any memory-based mitigation developed by Microsoft," explains the McAfee team. The .hta content is said to be disguised as a normal RTF file to evade security products.

Advertisement

"The successful exploit closes the bait Word document, and pops up a fake one to show the victim. In the background, the malware has already been stealthily installed on the victim's system," adds the team.

Advertisement

McAfee team has suggested some mitigation against the new zero-day attack before Microsoft issues an official patch including enabling the Office Protected View as the new exploit cannot bypass the Office Protected View, and do not open any Office files obtained from untrusted locations.

"We notified the Microsoft Security Response Center as soon as we found the suspicious samples, and we will continue to work with them to protect Office users," the team wrote in a blog post.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15 Price in India May Have Leaked via Listing Ahead of Launch
  2. Latest Pixel Drop Brings Several New Features to Pixel Phones
  3. OnePlus 15 Launching Today: Everything You Need to Know
  4. Vivo X300 Series Teased to Launch Soon in India
  5. OnePlus Nord 6 Launch Timeline Revealed in New Leak
  6. Oppo Reno 15 Pro Features Leaked; Could Include a Reno 15C Model
  7. Perplexity, Anthropic and Others Might Have Leaked AI Secrets on GitHub
  8. OnePlus 15: Everything We Know Ahead of Tomorrow's India Launch
  9. Exclusive: iQOO 15's Launch Price Is Not What You'd Expect
  10. Realme Neo 8 Could Launch With 8,000mAh Battery and More
  1. Aadhaar vs mAadhaar Key Differences Explained
  2. OnePlus 15 Launching Today: Know Price in India, Features, Specifications and More
  3. Sangarsha Ghadana - The Art of Warfare OTT Release Date: When and Where to Watch it Online?
  4. Merv To Stream on Prime Video Soon: What You Need to Know Zooey Deschanel and Charlie Cox Heartwarming Rom-Com
  5. Mano Ya Na Mano Now Streaming on YouTube: Know Everything About Cast, Plot, and More
  6. Search for the Truth OTT Release Date: When and Where to Watch it Online?
  7. Night Swim OTT Release Date: Everything You Need To Know About This Supernatural Horror
  8. Haq OTT Release Date Reportedly Revealed Online: Know When and Where to Watch it Online?
  9. Freakier Friday OTT Release Date: Know When and Where to Watch it Online?
  10. Thamma OTT Release Date Reportedly Revealed: When and Where to Watch Ayushmann Khurrana and Rashmika Mandanna’s Horror Comedy Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.