IT News
265

CVE-2021-40444 : New Microsoft Office zero-day used in attacks to execute PowerShell






  31-May-2022 22:19:04



CVE-2021-40444 : New Microsoft Office zero-day used in attacks to execute PowerShell

Microsoft Office zero day found by accident

Last Friday, security researcher nao_sec found a malicious Word document submitted to the Virus Total scanning platform from an IP address in Belarus.

"I was hunting files on VirusTotal that exploited CVE-2021-40444. Then I found a file that abuses the ms-msdt scheme," nao_sec told BleepingComputer in a conversation.

"It uses Word's external link to load the HTML and then uses the ‘ms-msdt’ scheme to execute PowerShell code,” the researcher added in a tweet, posting a screenshot of the obfuscated code below:



https://www.bleepingcomputer.com/news/security/new-microsoft-office-zero-day-used-in-attacks-to-execute-powershell/ 

*Beware click the link!


DISCUSSION
Nothing comment here :(
Login for report, comment and join discussion
Login Here
Sponsored

Popular Posts
Gps Tracker Seccodeid Free Too...
General
22101
208
Top


Djie sam soe Djie sam soe
Complete Basic Course in Kali...
Linux
15040
4
Top


Djie sam soe Djie sam soe
Free Proxy List
Networking
3818
3
Top


Sandidi Sandidi
Need ida pro crack anyone have...
Reverse Engineering
2884
29
Top


Member Seccodeid Rei
Xampp msyql error cant running
Web Development
2435
25
Top


Karno si kribo Karno si kribo

Related Post

Youtube Video

Subscribe