Thứ Hai, Tháng Hai 6, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Beware of tricks to attach Viruses to the latest Word File 2022

31 Tháng Năm, 2022
in Tech
0
Beware of tricks to attach Viruses to the latest Word File 2022
585
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

On May 30, 2022, cybersecurity expert John Hammond released a video exploiting a vulnerability through Windows’ Preview feature for Word files that could trigger malicious code to be attached. Currently, although there is no CVE, how to do it has been publicly announced.

It can be said that this is a zero-day vulnerability in Microsoft Office because there is currently no patch, hackers are actively exploiting in Word documents with malicious code attached to remotely execute code on the victim’s PC.

The vulnerability, named “Follina”, is used to exploit the way Office products work with MSDT (Microsoft Error Diagnostic Tool), which can be exploited even with macros disabled. in Microsoft Office.

According to some information, the vulnerability was initially reported to Microsoft’s security team on April 12, 2022, after Word files impersonating the Russian news agency Sputnik were distributed to users.

Nine days later, Microsoft decided that the vulnerability was not security related and therefore did not resolve. Unfortunately, that seems to be a wrong decision by Microsoft’s security team. Security researcher Kevin Beaumont reports this vulnerability works on the latest versions of Microsoft Office, even when updated to the latest version.

The “Follina” vulnerability came to light after an independent cybersecurity research group named what_sec detects a Word document (“05-2022-0438.doc“) uploaded to VirusTotal from an IP address in Belarus.

“This vulnerability uses Word’s external link to load HTML and then uses the ‘ms-msdt’ scheme to execute PowerShell code.” Word files with malicious code attached remote template of Word to fetch the HTML File from the server, then use the Schema URI “ms-msdt://” to download the malicious code and execute it on the victim’s computer.

The name is so named because the malicious sample references 0438, which is the area code for Follina, a municipality in the Italian city of Treviso.
You can watch the PoC video below:

MS-MSDT “Follina” Office click-to-hack. pic.twitter.com/v0DOkQhZjq

— John Hammond (@_JohnHammond) May 30, 2022

Now author John Hammond has published the file PoC on Github, those who want to study can download the test. I do not recommend using this method to send Word files with malicious code attached to others, so it will be against the law.

How to prevent the Follina vulnerability

Currently Office 2013, 2016, 2019, 2021 and Microsoft 365 versions on both Windows 10 and Windows 11 are affected by this vulnerability and Microsoft has not yet patched it. The temporary fix is ​​to turn off Preview mode in Windows Explorer by Open Windows Explorer -> View -> turn off the Preview Pane place

Turn off the Preview Pane– Download files unregister-msdt.reg then open the file to set and apply in Regedit. If the User Account Control window appears, select Yes.

– When receiving Word files from others or downloading from the Internet, check with Virustotal See if there is malicious code attached?

– If you receive a Word, Excel or PPT file, please upload it to Google Docs, Sheets or Slides to view Online instead of using Microsoft Office software.

General News

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
Previous Post

The Best Apps Every Student Should Use

Next Post

Russia controls parts of Severo Donetsk city

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
Russia controls parts of Severo Donetsk city

Russia controls parts of Severo Donetsk city

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem