ZeroHour
CyberScooppublished ()ingested @jeffstone500

Scammers are trying to exploit coronavirus concerns to breach companies

criticalPhishing & fraud exploited in the wildimportance 60CVE-2017-11882

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-11882
Memory Corruption RCE in Microsoft Office via Legacy Equation Editor

CVE-2017-11882 is a memory corruption vulnerability (CWE-119) in Microsoft Office, residing in the legacy Microsoft Equation Editor component (EQNEDT32.EXE), that allows remote code execution in the context of the current user. Attackers trigger it by persuading a user to open a crafted document, most commonly an RTF file or other Office document carrying a malicious embedded equation object, which overflows a buffer while the equation content is parsed. Successful exploitation lets the attacker run arbitrary code with the privileges of the signed-in user, a typical foothold for malware delivery and, per CISA, for ransomware operations. Any environment running affected Microsoft Office builds is exposed; the source data does not enumerate specific affected version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and holds a 99.9% EPSS score (percentile 100), though the source data lists no public PoC.

Do: Apply Microsoft's Office security updates (November 2017 or later) across all endpoints, prioritizing this KEV-listed flaw given its known ransomware use. On systems that cannot yet be patched, disable or unregister the legacy Equation Editor (EQNEDT32.EXE) and consider blocking or warning on RTF attachments as interim mitigations. Check for indicators of abuse such as EQNEDT32.EXE spawning unexpected child processes after document opens.

7.8100% KEV ransomware PoC ×10
  • Microsoft Office
masshundreds of millions of users/installations (Office is near-ubiquitous on Windows and in enterprises; the share still unpatched is unknown)
Full article591 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Phishing attempts come with a Microsoft Word document that activates a strain of malicious software, AZORult, which allows attackers to make off with sensitive data.

coronavirus
An official prepares a thermal scanner camera to check the body temperature of arriving passengers at Don Mueang Airport, in Bangkok, Thailand, on Feb. 7, 2020. (Anusak Laowilas/NurPhoto via Getty Images)

Hackers are preying upon fears about the new coronavirus from China by sending companies malicious emails cloaked as warnings about the economic repercussions that could occur as the illness spreads.

Researchers from the email security firm Proofpoint discovered a series of phishing attempts aimed at businesses in sectors that are particularly vulnerable to a disruption in trade because of the coronavirus, such as manufacturing, transportation and finance.

The messages feature subject lines like “Coronavirus – Brief note for the shipping industry,” then direct recipients to download a Microsoft Word document promising more information. That Word file activates a strain of malicious software, AZORult, which allows attackers to make off with sensitive data.

“The malware actors doing this appear to be from Russia and Eastern Europe, and while they aren’t part of an [advanced persistent threat] group, they clearly understand the economic concerns surrounding the Coronavirus,” Sherrod DeGrippo, Proofpoint’s senior director for threat research and detection, wrote in a blog post.

The coronavirus, a respiratory sickness that claimed the lives of more than 900 as of Sunday, has infected some 40,000 people. Quarantines, travel disruptions and widespread concerns about catching illness have upended the economic situation throughout Asia. The virus is a close cousin to the SARS and MERS viruses that provoked global responses in 2003 and 2012, health officials say.

The pathogen might be new to humans, but the hackers behind the phishing attempts are trying to exploit a vulnerability that’s more than two years old, called CVE-2017-11882, Proofpoint says.

“This underscores that the threat potential around Coronavirus remains broad and everyone should exercise caution when dealing with Coronavirus-themed emails, links and attachments, DeGrippo wrote. “While this recent effort was narrow in focus, we are seeing Coronavirus email lures increasingly mixed in with regular ones.”

For cybercriminals, this tactic is hardly new. Scammers of all sorts have worked to exploit attention and concerns on global crises, from natural disasters to sudden geopolitical events, like the U.S. killing of Iranian Gen. Qassem Soleimani.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/coronavirus-phishing-emails-proofpoint-research/