Security News > 2022 > June > Symantec: More malware operators moving in to exploit Follina

Symantec: More malware operators moving in to exploit Follina
2022-06-09 11:45

While enterprises are still waiting for Microsoft to issue a fix for the critical "Follina" vulnerability in Windows, yet more malware operators are moving in to exploit it.

"Symantec has observed attackers using a similar HTML file to that used in the initial attack. Multiple attackers are using a variety of payloads at the end of successful exploitation."

Follina is a RCE vulnerability in the Microsoft Support Diagnostic Tool that allows attackers to subvert the ms-msdt protocol handler process.

Attackers can use a specially crafted Word document that loads a malicious HTML file through the application's remote template function, according to Symantec.

Threat hunters with cybersecurity vendor Kaspersky also have been tracking attacks using the Follina flaw, noting in a blog post this week that organizations in the US are particularly being targeted.

"We expect to see more Follina exploitation attempts to gain access to corporate resources, including for ransomware attacks and data breaches," they wrote.


News URL

https://go.theregister.com/feed/www.theregister.com/2022/06/09/symantec-follina-microsoft/