Microsoft Warns of Unpatched Office Vulnerability Leading to Data Exposure
Summary: The flaw was discovered and reported by security researchers Jim Rush and Metin Yunus Kandemir. According to Microsoft's advisory an attacker could host a website or leverage a compromised website that accepts or hosts user-provided content. This site would contain a specially crafted file designed to exploit the vulnerability. However, the attacker cannot force the user to visit the malicious website. Instead, the attacker must lure the user into clicking a link—typically delivered via email or instant messaging—and then convince the user to open the specially crafted file, which would trigger the exploit. Link(s):
Microsoft has revealed a critical, unpatched zero-day vulnerability in Office that could lead to the unauthorized disclosure of sensitive information if successfully exploited. This vulnerability, tracked as CVE-2024-38200 with a CVSS score of 7.5, is classified as a spoofing flaw and impacts multiple versions of Office, including:
Security Officer Comments:
Microsoft has acknowledged the seriousness of the vulnerability and announced that a formal patch for CVE-2024-38200 will be released on August 13, 2024, as part of its monthly Patch Tuesday updates. In the meantime, the company has identified an alternative fix, which has already been enabled via a process called Feature Flighting as of July 30, 2024. This interim measure provides some level of protection across all in-support versions of Microsoft Office and Microsoft 365.
Suggested Corrections:
https://thehackernews.com/2024/08/microsoft-warns-of-unpatched-office.html