Tuesday, May 13, 2025
HomeComputer SecurityUnpatched Critical Bug in Microsoft Word Online Video Feature Allow Attacker to...

Unpatched Critical Bug in Microsoft Word Online Video Feature Allow Attacker to Deliver Powerful Malware

Published on

SIEM as a Service

Follow Us on Google News

An unpatched bug that abusing Microsoft word Online Video future that allow an attacker to deliver malicious files into the victim’s system.

A bug that existing in the JavaScript code execution within the office-embedded video component leads attackers to execute the malicious code.

This flaw affected Office 2016 and older versions and it will not produce any security warning while victims opening the document.

- Advertisement - Google News

Researchers built a Proof-of-concept for this attack using youtube video link with word document and demonstrate the infection process.

This flaw allows let an attacker execute the powerful malware or ransomware also they will use the evasion technique to avoid the security software detection.

How Does This Attack Works

Malicious hackers having an embedded video link inside of the Microsoft word document and send to victims via phishing mail that trick users to open it.

Embedded video contains a link that pointed to YOUTUBE and the hidden html/javascript code that will be running in the background.

According to cymulate, This attack is carried out by embedding a video inside a Word document, editing the XML file named document.xml, replacing the video link with a crafted payload created by the attacker which opens Internet Explorer Download Manager with the embedded code execution file.

Embed an online video option within the word document and link any YouTube video and save the document.

Later unpack the word document using unpacker or change the extension as zip and unzip it where you can find the several files along with word folder.

Word document contains a file called document.xml and find the  embeddedHtml parameter in order to identify the Youtube iframe code and Replace the current iframe code with any html code / javascript to be rendered by Internet Explorer.

A researcher from cymulate created a PoC that contains the embedded executable (as a blob of a base64). Once run, this code will use the msSaveOrOpenBlob method to trigger the download of the executable by opening Internet Explorer Download Manager with the option to run or save the file.

Mitigation:

Block Word documents containing the tag: “embeddedHtml” in the Document.xml file of the word documents.

Block word documents containing an embedded video.

Read:

Patched MS Office RCE Vulnerability Again Abused Windows Installer and Delivering a Keylogger

SmokeLoader Malware Abusing MS Office Document and Compromise Windows 8 ,10 Users PC

Lazarus Hacking Group Delivering RATANKBA Malware & Remote Hacking Tool Via MS Office Documents

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Scattered Spider Launches Supply Chain Attacks on UK Retail Organizations

Scattered Spider, also known as Roasting 0ktapus and Scatter Swine, has emerged as a...

Hackers Abuse PyInstaller to Deploy Stealthy macOS Infostealer

Jamf Threat Labs has identified a novel macOS infostealer that exploits PyInstaller, a legitimate...

PupkinStealer Targets Windows Users to Steal Browser Login Credentials

A newly identified information-stealing malware dubbed PupkinStealer has emerged as a significant threat to...

Repeated Firmware Key-Management Failures Undermine Intel Boot Guard and UEFI Secure Boot

The security of fundamental technologies like Intel Boot Guard and UEFI Secure Boot has...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Researchers Uncover Remote IT Job Fraud Scheme Involving North Korean Nationals

The United States indicted fourteen North Korean nationals for orchestrating a sophisticated scheme to...

Lumma Stealer Upgraded with PowerShell Tools and Advanced Evasion Techniques

Sophos Managed Detection and Response (MDR) in September 2024, the notorious Lumma Stealer malware...

New Noodlophile Malware Spreads Through Fake AI Video Generation Platforms

Cybercriminals have unleashed a new malware campaign using fake AI video generation platforms as...