HomeTechnologyMicrosoft warns of unpatched Office vulnerability that lets attackers steal sensitive data: All the details

Microsoft warns of unpatched Office vulnerability that lets attackers steal sensitive data: All the details

Microsoft has disclosed a serious security flaw in its Office suite, that could allow hackers to gain confidential data through malicious websites. A patch to fix this issue will be released on August 13.

August 13, 2024 / 14:59 IST
Story continues below Advertisement
Office
Office

 

Microsoft has revealed that there is a serious security flaw in their Office software service, which can be used by threat actors to access sensitive information. It has been described as a spoofing flaw that uses social engineering to lure users to click on maliciously crafted links, which are aiming to mimic the original websites.

Story continues below Advertisement

This vulnerability is identified as CVE-2024-38200 and rated 7.5 on the Common Vulnerability Scoring System (CVSS) scale. It was discovered by security researchers Jim Rush and Metin Yunus Kandemir, who subsequently reported it to Microsoft. The vulnerability can also be exploited through malicious files disguised as legitimate documents.

Microsoft has also stated this issue and added, "In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability.”