Microsoft Word Vuln Went Unnoticed for 17 Years: Report

  /     /     /  
Publicated : 22/11/2024   Category : security


Microsoft Word Vuln Went Unnoticed for 17 Years: Report


Researchers claim Microsoft Word vulnerability, patched today, has existed for 17 years.



Microsoft today rolled out 53 security patches for the month of November as part of its regular Patch Tuesday update. One of the fixes addresses CVE-2017-11882, a flaw that has existed, unnoticed, in Microsoft Word for the past 17 years.
The fixes announced today address flaws in Windows, Internet Explorer, Office, Edge, ASP.NET Core, .NET Core, and Chakra Core. Twenty of the CVEs are labeled Critical, 30 are ranked Important, and three are Moderate. Three of the bugs today are publicly known but none are categorized as being under active attack, and there were no zero-days this month.
Researchers at Embedi, a firm specializing in security for embedded devices, today released a report on a 17-year-old remote code execution vulnerability in Microsoft Office, which was patched today. They claim it has not been patched and Microsoft did not know it existed.
CVE-2017-11882 is a Microsoft Office Memory Corruption Vulnerability,
Microsoft reports
. It exists in Office software when the software doesnt properly handle objects in memory. If successfully exploited, it could let an attacker run arbitrary code in the context of the user.
If a user has administrative privileges, an attacker who took advantage of this exploit could take control of an infected system and install programs, view and edit data, or create new accounts with full user rights. Microsoft says this CVE is more dangerous for administrative users.
CVE-2017-11882 could be exploited with a phishing attack; victims need only to open a malicious file with an affected version of Microsoft Office or Microsoft WordPad. In a web-based attack, an attacker could host a website with a malicious file designed to exploit the CVE.
The exploit was created by Embedi experts, who report it works with all Microsoft Office versions released in the past 17 years, including Office 365. It works on versions of Microsoft Windows, including the Creators Update, and its relevant for all types of architecture. This flaw doesnt interrupt a users work within Microsoft Office, Embedi
explains
. Once the document is opened, it doesnt require any further user interaction.
The only hindrance here is the protected view mode because it forbids content execution (OLE/ActiveX/Macro), researchers say. However, this could be bypassed with social engineering. An attacker could, for example, ask a user to save a file to the cloud using OneDrive or Google Drive. When opened, protected view mode would not be enabled.
Embedi researchers reported the vulnerability to Microsoft in March 2017 and the final fix was issued today.
Greg Wiseman, senior security researcher at Rapid7, points out CVE-2017-11882 as one of the flaws which could be especially dangerous.  
No non-browser vulnerabilities are considered critical this month, but with a little bit of social engineering, an attacker could theoretically combine one of the Office-based RCE vulnerabilities like CVE-2017-11878 or CVE-2017-11882 with a Windows Kernel privilege escalation weakness such as CVE-2017-11847 to gain complete control over a system, he says.
Related Content:
New Locky Ransomware Takes Another Turn
Frequent Software Releases, Updates May Injure App Security
Customers Punish Breached Companies
Cybersecurity Staffing Shortage Tied to Cyberattacks, Data Breaches
Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity
agenda here
.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Microsoft Word Vuln Went Unnoticed for 17 Years: Report