Live data from Hacker News

Microsoft: 0Day Exploit Targeting Word, Outlook

krebsonsecurity.com

1–10 of 43 posts

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#3
post #2

Well there goes half of .gov and .mil... (at least the agencies not forcing plain text email)

Fortunately, I think the current exploits rely on ActiveX controls which are disabled when reading Outlook RTF messages. In fact, I have seen no real world Word exploits using Outlook RTF messages, probably because spear phishing is effective enough.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#4
post #3
post #2

Well there goes half of .gov and .mil... (at least the agencies not forcing plain text email)

Fortunately, I think the current exploits rely on ActiveX controls which are disabled when reading Outlook RTF messages. In fact, I have seen no real world Word exploits using Outlook RTF messages, probably because spear phishing is effective enough.

The advisory says that Office for Mac 2011 is also affected, implying that it's not related to ActiveX controls.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#6
Everyone in my office runs MS Office for inane reasons, I did try to make them move to openoffice/libreoffice w/ thunderbird, we run an open stack behind the scenes and things simply integrate better..

I feel like this is a massive 'told ya so' after spending thousands of pounds of company money on licenses, now I'll have to spend hours of my time fixing everyones machine one by one, just in case. >_hopefully a fix comes in soon and I don't have to worry too much, I assume it will but getting everyone to update (well, forcing it) is a bit hard too.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#7
post #6

Everyone in my office runs MS Office for inane reasons, I did try to make them move to openoffice/libreoffice w/ thunderbird, we run an open stack behind the scenes and things simply integrate better.. I feel like this is a massive 'told ya so' after spending thousands of pounds of company money on licenses, now I'll have to spend hours of my time fixing everyones machine one by one, just in case. >_ hopefully a fix…

Serious question -- I don't intend to troll -- I've heard lots of people claim that as soon as OpenOffice et al. get more popular, more malware will target them. It's not as if Microsoft has a monopoly on bugs. Do you think there's ay truth to this line of thinking?

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#8
post #6

Everyone in my office runs MS Office for inane reasons, I did try to make them move to openoffice/libreoffice w/ thunderbird, we run an open stack behind the scenes and things simply integrate better.. I feel like this is a massive 'told ya so' after spending thousands of pounds of company money on licenses, now I'll have to spend hours of my time fixing everyones machine one by one, just in case. >_ hopefully a fix…

It looks like the temporary fix is just adding a registry key[1]. This can be automated via login scripts or pushed in a SCCM package.

1: https://technet.microsoft.com/en-us/security/advisory/295309...

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#9
post #6

Everyone in my office runs MS Office for inane reasons, I did try to make them move to openoffice/libreoffice w/ thunderbird, we run an open stack behind the scenes and things simply integrate better.. I feel like this is a massive 'told ya so' after spending thousands of pounds of company money on licenses, now I'll have to spend hours of my time fixing everyones machine one by one, just in case. >_ hopefully a fix…

A quick search reveals arbitrary code vulnerabilities in OpenOffice, too, so what's your point? Large surface area apps written in C++ will probably always have these issues.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#10
post #6

Everyone in my office runs MS Office for inane reasons, I did try to make them move to openoffice/libreoffice w/ thunderbird, we run an open stack behind the scenes and things simply integrate better.. I feel like this is a massive 'told ya so' after spending thousands of pounds of company money on licenses, now I'll have to spend hours of my time fixing everyones machine one by one, just in case. >_ hopefully a fix…

Serious question -- I don't intend to troll -- I've heard lots of people claim that as soon as OpenOffice et al. get more popular, more malware will target them. It's not as if Microsoft has a monopoly on bugs. Do you think there's ay truth to this line of thinking?

From a security situation, the worst situation is everyone running different mail clients, because then if any one of them has a vulnerability someone can send in a crafted mail to take over their box and gain access to your private company docs.

"Monoculture" isn't always bad.

Post reply on HN