A new vulnerability in Microsoft Word allows attackers to bypass all the Anti-Malware Defences

A new vulnerability that affects Microsoft Word has been discovered by a group of researchers from Mimecast Research Labs. The vulnerability affects Microsoft Word and Microsoft seems disinterested in patching it any time soon.

The researchers confirmed a bug that allows hackers to evade all security measures such as antimalware on the target system. The flaw targets the way Microsoft handles Integer Overflow errors in OLE file format. A group of hackers based out of Syria has exploited the OLE vulnerability to bypass all security measures.

The group was able to exploit this bug to circumvent many security solutions designed to protect data from infestation, including leading sandbox and anti-malware technologies.

Malware code reveals that it is capable of visiting URLs, creating files and/or folders, running shell commands, and executing and ending programs. It can also steal information by logging keystrokes and mouse events.

Mimecast Research Labs has already informed Microsoft about the vulnerability but the company said it’s not interested in fixing it right now.

Microsoft acknowledged it was unintended behavior, but declined to release a security patch at this time, as the issue on its own does not result in memory corruption or code execution. The issue may be fixed at a later date.

Via: Latest Hacking News

Some links in the article may not be viewable as you are using an AdBlocker. Please add us to your whitelist to enable the website to function properly.

Related
Comments