logo
logo
Sign in

Microsoft, CISA urge use of mitigations and workarounds for Office document vulnerability

avatar
Mahendra Patel
Microsoft, CISA urge use of mitigations and workarounds for Office document vulnerability

An unpatched vulnerability found in the MSHTML engine is enabling attacks on Microsoft Office users. This Vulnerability is tracked as CVE-2021-40444, and is being used in targeted attacks featuring specially crafted Office documents. It could enable a remote attacker to hijack an affected system. 

Malicious ActiveX can be used by an attacker on a Microsoft Office document that hosts the browser rendering engine. The documents most likely arrive as e-mail message attachments. Once they are downloaded and opened, they can take over the victim's computer, especially if they have built-in social engineering tools which can trick users into allowing administrative access. Users whose accounts operate with administrative user rights would be most at risk as opposed to those whose accounts have fewer user rights on a system. 

For More Information: Microsoft, CISA urge use of mitigations and workarounds for Office document vulnerability 

collect
0
avatar
Mahendra Patel
guide
Zupyak is the world’s largest content marketing community, with over 400 000 members and 3 million articles. Explore and get your content discovered.
Read more