IT News
204

CVE-2021-40444 : New Microsoft Office zero-day used in attacks to execute PowerShell






  31-May-2022 22:19:04



CVE-2021-40444 : New Microsoft Office zero-day used in attacks to execute PowerShell

Microsoft Office zero day found by accident

Last Friday, security researcher nao_sec found a malicious Word document submitted to the Virus Total scanning platform from an IP address in Belarus.

"I was hunting files on VirusTotal that exploited CVE-2021-40444. Then I found a file that abuses the ms-msdt scheme," nao_sec told BleepingComputer in a conversation.

"It uses Word's external link to load the HTML and then uses the ‘ms-msdt’ scheme to execute PowerShell code,” the researcher added in a tweet, posting a screenshot of the obfuscated code below:



https://www.bleepingcomputer.com/news/security/new-microsoft-office-zero-day-used-in-attacks-to-execute-powershell/ 

*Beware click the link!


DISCUSSION
Nothing comment here :(
Login for report, comment and join discussion
Login Here
Sponsored

Popular Posts
Gps Tracker Seccodeid Free Too...
General
21371
204
Top


Djie sam soe Djie sam soe
Complete Basic Course in Kali...
Linux
14395
4
Top


Djie sam soe Djie sam soe
Komintod (Ministry of Communic...
Data Leak
6525
98
Top


Murtad methamphetamine Murtad methamphetamine
Free Proxy List
Networking
3626
3
Top


Sandidi Sandidi
Mass Reverse IP Unlimited
Tools Hacking
3405
15
Top


ImamWawe ImamWawe

Related Post

Youtube Video

Subscribe