Friday, November 8, 2024
Friday, November 8, 2024
- Advertisement -

Number of exploits for vulnerabilities in Microsoft Office suite increases 

Kaspersky finds eight times more users attacked via an old Microsoft Office vulnerability

Must Read

- Advertisement -
- Advertisement -
  • Accounts for 82% of the total number of exploits across different platforms in second quarter.

The number of exploits for vulnerabilities in the Microsoft Office suite increased in the second quarter of this year, accounting for 82 per cent of the total number of exploits across different platforms, a Kaspersky report showed.

In the first quarter of this year, vulnerabilities in Office suite accounted for 78.50 per cent.

Old versions of applications remain the main targets for attackers, with almost 547,000 users in total being affected through corresponding vulnerabilities in the last quarter.

Moreover, the number of users affected by the Microsoft MSHTML Remote Code Execution vulnerability, which was previously spotted in targeted attacks, skyrocketed eight times.

Social engineering techniques

The zero-day vulnerability in Internet Explorer’s engine MSHTML was first reported in September 2021.

The engine is a system component used by Microsoft Office applications to handle web content. When exploited, it enables the remote execution of malicious code on victims’ computers.

 “Since the vulnerability is quite easy to use, we expect an increase in its exploitation,”  Alexander Kolesnikov, malware analyst at Kaspersky, said in a statement.

Moreover, he said that criminals craft malicious documents and convince their victims to open them through social engineering techniques.

“The Microsoft Office application then downloads and executes a malicious script. To be on the safe side, it is vital to install the vendor’s patch, use security solutions capable of detecting vulnerability exploitation, and to keep employees aware of modern cyberthreats.”

Related posts:



Sign up to receive top stories every day

- Advertisement -

Latest News

Schneider Electric becomes ransomware victim for third time

Ransomware gang HellCat demands $125,000 from Schneider Electric in “baguettes”

Apple invests $1.5b in Globalstar to boost satellite communications

Apple will contribute $1.1b in cash while acquiring 20% equity in Globalstar for $400m

Apple to swallow Pixelmator to bolster its creative software lineup

Apple users can anticipate exciting developments that will further enhance their creative endeavours
- Advertisement -
- Advertisement -

More Articles

- Advertisement -