Telecom Tidbits
Jared's Network and Security Blog
  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links

Microsoft Office: No Shortage of Exploits

September 22, 2017 Jared Hall General

There exists another vulnerability (of sorts) within Microsoft Word that is actively being exploited for espionage and surveillance purposes. What is happening is that a Unicode reference to the INCLUDEPICTURE field can include a hyperlink to an external image or file, like a PHP script on a remote server. This is an OLE2 (Object Linking and Embedding) directive, first introduced in Office 2007.

So without the need for executable code, scripts, or contaminated document objects, your PC can fork over valuable system hardware and software information. At present, this is being used for information gathering purposes only; suggesting a precursor for an attack campaign. This bug exists in all versions of Office since 2007, including the Apple and Android versions.

Generally speaking, keep a tight reign on Office documents. People who continue to Email Office documents around will get burned. This is not a question of “if“, but of “when“.

Kaspersky’s ThreatPost has an interesting write-up on this issue here.

« VMware Exploited Again: Update Now » SSL/TLS Email Connection Testing

Tools & Downloads

Download Center

Categories

Good Reads (PDF)

Recent Posts

  • PayPal Woes and Degenerative AI
  • A Pathetic Defense of Julian Assange
  • Damned if you do. Damned if you don’t.
  • ProtonMail? Not Worth an Electron!
  • Give it a REST: Serious WordPress Bugs
$
Select Payment Method
Personal Info

Donation Total: $20.00

↑

  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links
Temporal Based Intelligence © 2017