New zero day vulnerability being exploited
Full article290 words · extracted from securelist.com · click to collapse
The Internet Storm Center is reporting a new zero day vulnerability in Microsoft Word. We don’t yet know if the exploit is being widely used. However, early reports indicate a limited, targeted, attack.
Malware which spreads via email is exploiting the vulnerability as a specially crafted MS-Word .DOC attachment.
If the attachment is launched, this triggers a process which results in a backdoor being installed.
We know of a case where the attacker designed the email to fool the recipient into thinking the message was from a co-worker. At the moment, we’re only aware of one business, and maybe 5-10 people within that business, who have been targeted. Yes, it’s a new vulnerability, and new malware targeting that vulnerability, but as far as we know, it’s not being widely exploited at the moment.
We’ve released detection for the malware, a dropper and backdoor. As ever, users should update their databases as soon as possible. Kaspersky products will detect the dropper as Trojan-Dropper.MSWord.1Table.bd, and the backdoor as Backdoor.Win32.Gusi.a.
We’ll post more information once we’ve conducted a detailed analysis.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/new-zero-day-vulnerability-being-exploited/30168/