Security News > 2022 > May > Zero-day vuln in Microsoft Office: 'Follina' will work even when macros are disabled

Zero-day vuln in Microsoft Office: 'Follina' will work even when macros are disabled
2022-05-30 18:01

Infosec researchers have idenitied a zero-day code execution vulnerability in Microsoft's ubiquitous Office software.

Dubbed "Follina", the vulnerability has been floating around for a while and uses Office functionality to retrieve a HTML file which in turn makes use of the Microsoft Support Diagnostic Tool to run some code.

The Huntress post on the matter suggested users utilizing Microsoft Defender's Attack Surface Reduction rules could put the "Block all Office Applications from creating child processes" option into "Block mode."

An alternative suggested by vulnerability analyst Will Dormann would be to remove the file type association for ms-msdt to stop Office firing up the app.

"Detection," wrote Beaumont in a post on the subject, "Is probably not going to be great, as Word loads the malicious code from a remote template, so nothing in the Word document is actually malicious."

Interestingly, although Microsoft has yet to publicly acknowledge the issue, Beaumont noted that it appeared to have been fixed in the very latest Insider and Current versions of Office.


News URL

https://go.theregister.com/feed/www.theregister.com/2022/05/30/follina_microsoft_office_vulnerability/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 713 868 4788 4392 3717 13765