Critical Flaw in Microsoft Office Allows Cybercriminals to Exfiltrate Confidential Information

Microsoft has unveiled a critical flaw in its Office software, designated CVE-2024-38200, which could potentially enable unauthorized access to confidential data.

This spoofing issue impacts various versions of Microsoft Office, including Office 2016, Office 2019, Office LTSC 2021, and Microsoft 365 Apps for Enterprise, on both 32-bit and 64-bit platforms. With a CVSS score of 7.5, the vulnerability is deemed significant due to its potential to reveal sensitive information to unapproved individuals, falling under the CWE-200 category.

Despite its seriousness, Microsoft has assessed the probability of exploitation as “less likely,” suggesting that while the threat is notable, a widespread attack is not expected immediately.

In a typical exploit scenario, an attacker could set up a malicious website or compromise an existing site to deliver a specially crafted file to the target. The attacker would need to convince the victim to visit the site and open the file, often through misleading emails or instant messages. This reliance on user interaction is a key factor in the exploit’s feasibility.

Microsoft has already introduced a temporary fix via Feature Flighting as of July 30, 2024, to safeguard users on all supported versions of Microsoft Office and Microsoft 365. However, the company advises installing the formal patch scheduled for release on August 13, 2024, for thorough protection.

To reduce risk, Microsoft suggests several measures:

  • Limit NTLM Traffic: Configure network security policies to block or monitor outgoing NTLM traffic to remote servers.
  • Protected Users Security Group: Include high-value accounts in this group to prevent NTLM usage.
  • Block TCP 445/SMB: Employ firewalls to block outbound traffic on this port, reducing exposure to NTLM authentication messages.

This vulnerability was discovered by Jim Rush of PrivSec Consulting and Metin Yunus Kandemir of Synack Red Team. Further details will be shared during Rush’s presentation at DEF CON 2024, where he will discuss this and other security issues.

Microsoft continues to address other vulnerabilities, underscoring the necessity of keeping systems updated to avoid exploitation. Users are encouraged to stay alert and apply security patches promptly to protect their data.

More Articles & Posts