Microsoft Office and Windows HTML Remote Code Execution Vulnerability
Zero-day vulnerability CVE-2023-36884 is being exploited in the wild
Summary
Zero-day vulnerability CVE-2023-36884 is being exploited in the wild
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Microsoft have released details about a zero-day vulnerability affecting Word, Office, Windows, and Windows Server, known as CVE-2023-36884, which has a CVSSv3.1 score of 8.3. To exploit the vulnerability, an attacker could use social engineering to convince a user to open a malicious file, which could lead to remote code execution.
Microsoft has reported targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents.
Exploitation of CVE-2023-36884 and a blog regarding the abuse of this vulnerability by threat group Storm-0978
Microsoft has reported targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents.
Included in the advisory for this vulnerability is a link to Storm-0978 attacks reveal financial and espionage motives, a blog describing an identified phishing campaign conducted by a threat group that is targeting defence and government entities in Europe and North America. Microsoft provides mitigation and recommendations for protection of its customers in both the security advisory for CVE-2023-36884 and the blog post.
Remediation advice
Affected organisations are encouraged to read and consider the mitigation and recommendations in Microsoft's Security Advisory for CVE-2023-36884 and the blog post Storm-0978 attacks reveal financial and espionage motives.
Microsoft state that this CVE advisory will be updated with new information and links to security updates when they become available. Upon conclusion of its own investigation, Microsoft plans to take appropriate action, which may include providing a security update through its monthly release process or by providing an out-of-cycle security update.
Last edited: 12 July 2023 4:16 pm