Moneycontrol PRO
Black Friday Sale
Black Friday Sale
HomeTechnologyMicrosoft warns of unpatched Office vulnerability that lets attackers steal sensitive data: All the details

Microsoft warns of unpatched Office vulnerability that lets attackers steal sensitive data: All the details

Microsoft has disclosed a serious security flaw in its Office suite, that could allow hackers to gain confidential data through malicious websites. A patch to fix this issue will be released on August 13.

August 13, 2024 / 14:59 IST
Office

Microsoft has revealed that there is a serious security flaw in their Office software service, which can be used by threat actors to access sensitive information. It has been described as a spoofing flaw that uses social engineering to lure users to click on maliciously crafted links, which are aiming to mimic the original websites.

This vulnerability is identified as CVE-2024-38200 and rated 7.5 on the Common Vulnerability Scoring System (CVSS) scale. It was discovered by security researchers Jim Rush and Metin Yunus Kandemir, who subsequently reported it to Microsoft. The vulnerability can also be exploited through malicious files disguised as legitimate documents.

Microsoft has also stated this issue and added, "In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability.”

Further, the company has said, “However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file.”

Hence, Microsoft Office users are strongly advised to exercise caution when handling Office documents from unknown or untrusted sources. The official patch is expected to be released on August 13, as part of Microsoft’s regular security update cycle. Currently, the Office versions which are at risk are, Microsoft Office 2016, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, and Microsoft Office 2019.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Sandip Chakraborty
first published: Aug 13, 2024 02:59 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347