Fresh spam campaign targeting Microsoft Office with old malware

Cyber criminals are hitting European users with malicious RTF files that open up backdoor access

An active malware campaign is targeting Microsoft Office customers in Europe by distributing RTF files loaded with malicious code.

Although the flaw dubbed CVE-2017-11882 was fixed in 2017, Microsoft researchers have noticed a sharp rise in exploits for the remote code execution (RCE) vulnerability in the past few weeks.

The company's security intelligence team have warned about an increase in spam emails loaded with malware, which would allow an attacker to run malicious code on a user's machine without any interaction on their front. The messages are also being written in several European languages, suggesting its targets lie mainly in the UK and wider Europe.

"The CVE-2017-11882 vulnerability was fixed in 2017, but to this day, we still observe the exploit in attacks," the Microsoft team said. "Notably, we saw increased activity in the past few weeks. We strongly recommend applying security updates."

Once the attached RTF file is loaded, it will launch multiple scripts including PowerShell and PHP to download the payload, which in this case is a backdoor trojan. This will attempt to connect to a malicious domain which has been disconnected at the time of writing.

Advertisement - Article continues below

The vulnerability hinges on the Office software's failure to properly handle objects in memory. Specifically, the Microsoft Equation Editor, packaged into all supported versions of Microsoft Office since the year 2000, contains a stack buffer overflow vulnerability.

Advertisement
Advertisement - Article continues below

An attacker could take control of an affected system if a user is logged on with administrative rights, and then install other programs, or delete data. They could also create new user accounts with full administrative rights.

Microsoft fixed the vulnerability in November 2017, but it remains a popular method of attack among cyber criminals and continues to be actively exploited in various campaigns. It was, in fact, the third most widely-used exploit in 2018 according to analysis by IT firm Recorded Future.

This is because many users haven't yet implemented fixes to the software and are still considered ripe targets for a vulnerability that was fixed more than a year and a half ago.

Featured Resources

Successful digital transformations are future ready - now

Research findings identify key ingredients to complete your transformation journey

Download now

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The future of database administrators in the era of the autonomous database

Autonomous databases are here. So who needs database administrators anymore?

Download now

The IT expert’s guide to AI and content management

Your guide to the biggest opportunities for IT teams when it comes to AI and content management

Download now
Advertisement

Recommended

Visit/security/cyber-security/355267/zoom-hires-ex-facebook-cso-to-boost-platform-security
cyber security

Zoom hires ex-Facebook CSO Alex Stamos to boost platform security

8 Apr 2020
Visit/security/vulnerability/355236/hp-support-assistant-flaws-leave-windows-devices-open-to-attack
vulnerability

HP Support Assistant flaws leave Windows devices open to attack

6 Apr 2020
Visit/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs
cyber security

Safari bug let hackers access cameras on iPhones and Macs

6 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020

Most Popular

Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
Visit/development/application-programming-interface-api/355192/apple-buys-dark-sky-weather-app-and-leaves
application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020
Visit/server-storage/servers/355254/a-critical-flaw-in-350000-microsoft-exchange-remains-unpatched
servers

A critical flaw in 350,000 Microsoft Exchange remains unpatched

7 Apr 2020