Auteur Sujet: [Trend]April Patch Tuesday: Microsoft Patches Office Vulnerability Used in Zero-Day Attacks  (Lu 2945 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
April Patch Tuesday: Microsoft Patches Office Vulnerability Used in Zero-Day Attacks

One of the major updates for this month’s Patch Tuesday addresses CVE-2017-0199, a zero-day remote code execution vulnerability that allowed attackers to exploit a flaw that exists in the Windows Object Linking and Embedding (OLE) interface of Microsoft Office. This flaw is currently being exploited by the notorious DRIDEX banking trojan.


Threat actors leveraging this vulnerability do so via a spam campaign in which the attacker sends an email with an embedded Microsoft Word document to a targeted user. When the user opens the attached document, the hidden exploit code connects to a remote server that fetches malicious files, which are DRIDEX variants(detected by Trend Micro as TSPY_DRIDEX.SLP, TROJ_CVE20170199.B and TROJ_CVE20170199.C).


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


April Patch Tuesday: Microsoft Patches Office Vulnerability Used in Zero-Day Attacks


Source: April Patch Tuesday: Microsoft Patches Office Vulnerability Used in Zero-Day Attacks

Tags: