Security News > 2021 > September > Recently reported Microsoft zero-day gaining popularity with attackers, Kaspersky says

Recently reported Microsoft zero-day gaining popularity with attackers, Kaspersky says
2021-09-17 18:43

A flaw in the MSHTML engine that lets an attacker use a malicious Office document to install malware is currently being used against the energy, industrial, banking, medical tech, and other sectors.

A recently reported security vulnerability in Microsoft's MSHTML browser engine is being found all over the world, and Kaspersky said it "Expects to see an increase in attacks using this vulnerability."

To make matters worse, the vulnerability is easy to exploit: All an attacker has to do is send a Microsoft Office document to the intended victim that contains a malicious script.

Like plenty of other attacks using malicious documents, the victim has to open the document in order to infect their machine with the attacker's actual payload, which is retrieved by the script in the document.

In the wild, Kaspersky said, most of the detected attacks install backdoors that give attackers additional access to the infected machine.

In situations where updating a Windows system may be difficult, Microsoft has published workarounds that disable ActiveX via group policy, disabled ActiveX with a custom registry key and a Windows Explorer preview disable registry edit that will prevent scripts from being run in without fully opening a document.


News URL

https://www.techrepublic.com/article/recently-reported-microsoft-zero-day-gaining-popularity-with-attackers-kaspersky-says/#ftag=RSS56d97e7

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 480 75 2308 5127 264 7774
Kaspersky 23 0 19 16 6 41