Get a Pentest and security assessment of your IT network.

News

Microsoft Office: Attackers Injecting Code Via Zero-Day Bug

Malicious Office documents designed to exploit the flaw can be triggered in multiple ways, including via a hover-preview in Windows Explorer, security firm Huntress warns. The vulnerability “uses Word’s external link to load the HTML and then uses the’ms-msdt’ scheme to execute PowerShell code” Microsoft on Monday confirmed the flaw and designated it CVE-2022-30190. The exploit chain allows an attacker to use MSDT to execute arbitrary PowerShell code on a system, which they can use to download and execute malicious code.”]

Source: https://www.databreachtoday.com/microsoft-office-attackers-injecting-code-via-zero-day-bug-a-19169

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2