مضى على الشبكة و يوم من العطاء.

Office and Windows HTML Remote Code Execution Vulnerability

BAYANBAYAN is verified member.

الرقابة والتنظيم
.:: الرقابة والتنظيم ::.
.:: طاقم المشرفين ::.

السمعة:

Executive Summary :

Microsoft is warning of an unpatched Office zero-day vulnerability that is being targeted by a Russian-based threat actor in phishing emails with the aim of delivering a backdoor on victim systems.

An attacker could create a specially crafted Microsoft Office document that enables remote code execution on the target’s computer. In order for the exploit to succeed, the victim needs to open the malicious file.

⬇️ Check the links below for more details ⬇️

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884

 
التعديل الأخير:
13 Jul 05-31

Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents.
An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.
هل كدة استخدام النظام نفسه حاليا ميعتبرش خطر ولكن الخطر من برامج الاوفيس وملفاته و ال phishing ؟؟؟
 
على حسب ما فهمت ف يب ؛ الخطر بس من الاوفيس يعني ممكن يستخدم ال Phishing حتى يوصلك فايل الاوفيس doc او docx ولازم تفتحه طبعا وقتها بيعمل backdoor وبيستغله ليعمل الـ RCE ، ولو ما كان بحاجة لأنه تفتح ملف او تعمل اكشن ف هون بنسميه zero click 👾
 
التعديل الأخير:
  • Like
التفاعلات: STORM

آخر المشاركات

فانوس

رمضان
عودة
أعلى