Linchakin

New Unpatched 0-Day Bug Actively Attack Windows By Abusing MS Office Documents

 September 08, 2021     No comments   

0-Day in MSHTML

Microsoft issued a warning to Windows users that hackers actively exploiting an unpatched remote code execution 0-Day vulnerability in MSHTML using lured MS office documents.

The MSHTML is a browser rendering engine that allows the Microsoft Internet Explorer Web browser to read and display HTML Web pages.

Attackers are abusing the Microsoft office document by craft a malicious ActiveX control that hosts in the browser rendering engine, and the vulnerability will be triggered when the victims open the malicious MS Office document.

Microsoft assigned a CVE-2021-40444 for this MSHTML Remote Code Execution Vulnerability and marked it as a high severity vulnerability with the  8.8/10 impact level.

According to a Microsoft report “Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents.”

“The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.”

The vulnerability was detected by EXPMON – An Environment-binding Exploit Detection Service and issued a public warning about this unpatched zero-day vulnerability.

💥💥⚡️⚡️
EXPMON system detected a highly sophisticated #ZERO-DAY ATTACK ITW targeting #Microsoft #Office users! At this moment, since there's no patch, we strongly recommend that Office users be extremely cautious about Office files – DO NOT OPEN if not fully trust the source!

— EXPMON (@EXPMON_) September 7, 2021

Also, the attack was successfully tested on the latest Office 2019 / Office 365 on Windows 10, and the attack highly sophisticated zero-day attack.

Also, a researcher from EXPMON said that the attackers exploit this vulnerability using a malicious .DOCX file that tricks the victim to open it, then loaded on the Internet Explorer engine that leads to rendering the remote we page crafted by the hackers.

Soon after the specific ActiveX control will drop the malware onto the victim’s device which is called by Microsoft as “: “Suspicious Cpl File Execution”.

Microsoft has also released a workaround for this 0-Day vulnerability through which Microsoft recommended disabling the installation of all ActiveX controls in Internet Explorer mitigates this attack.

Also said that ” This can be accomplished for all sites by updating the registry. Previously-installed ActiveX controls will continue to run, but do not expose this vulnerability.”

How to Disable the Activex Control:

According to the Microsoft report To disable installing ActiveX controls in Internet Explorer in all zones, paste the following into a text file and save it with the .reg file extension:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"1001"=dword:00000003
"1004"=dword:00000003

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"1001"=dword:00000003
"1004"=dword:00000003

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"1001"=dword:00000003
"1004"=dword:00000003

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1001"=dword:00000003
"1004"=dword:00000003

By installing ActiveX controls in Internet Explorer will prevent windows users from this 0-day vulnerability until Microsoft issue the security update which can be expected in this September Patch Tuesday update.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • The Radioactive Woman: Marie Curie Marie Curie, born Maria Salomea Skłodowska, was a self-sacrificing genius with an incredible work ethic and a complete disdain for money. Curie… Read More
  • ViewSonic Targets Gamers With 150 Hz 32-Inch Elite XG320U 4K HDMI 2.1 MonitorByBrandon Hill The ViewSonic Elite XG320U features a 4K IPS panel that me...ViewSonic expanded its gaming monitor lineup today with the reveal of the Elite XG320U. The Elite XG320U features a 4K IPS panel that measures 32 inch… Read More
  • HyperX Pulsefire RGB Mouse Mat Hands-On: Great for Larger DesksByMichelle Ehrhardt HyperX’s first XL sized RGB mouse mat, the Pulsefire RGB, fires on ... Today's best HyperX Pulsefire RGB Mouse Mat deals Like the best mechanical keyboards, large mouse mats that stretch far enough to put even a keybo… Read More
  • Can this cute but scary dino turn you vegan?ByTom May NewsVegamama is on a mission to convert you to plant-based food.Only one per cent of the UK population calls itself vegan. But Wagamama, a British restaurant Chain serving Japanese-inspired food is out to change th… Read More
  • Sony opens registration for invite-only PS5 restocks — how to sign upIncrease your chance of scoring a PS5 this holidayWinning at Sony PS5 restocks just got a little easier. Sony Direct is now allowing gamers to register for its invite-only PS5 restock events. Signing … Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates