Monday, November 25, 2024
HomeCVE/vulnerabilityPowerPoint file Equipped with CVE-2017-0199 could Compromise Your System

PowerPoint file Equipped with CVE-2017-0199 could Compromise Your System

Published on

Security experts from FortiGuard Labs discovered a malicious Powerpoint file in name ADVANCED DIPLOMATIC PROTOCOL AND ETIQUETTE SUMMIT.ppsx using the CVE-2017-0199 Vulnerability.By opening, this malicious PDF file may compromise your system.

CVE-2017-0199 was originally a zero-day remote code execution vulnerability that allowed attackers to use a flaw that exists within the Windows Object Linking and Embedding (OLE) interface of Microsoft workplace to deliver malware.

This vulnerability has been disclosed and patched in last April 2017. This vulnerability triggers an RCE with Microsoft Office or Word with specially crafted files.

- Advertisement - SIEM as a Service

Fortigate identified that the flaw is used by attackers in Windows Object Linking and Embedding (OLE) interface of Microsoft Office and gain control over the system.

Powerpoint Malware
Source : Fortinet

When the malicious file opened by the user it triggers ppt/slides/_rels/slide1.xml.rels and then it use to download remote code from hxxp://www[.]narrowbabwe[.]net:3345/exp[.]doc.The remote code developers include blank spaces to evade malware detection.

Also Read Exploit Windows Remote PC with EternalBlue & DoublePulsar Exploit through Metasploit

They observed that exploit to use to download the doc file and it consist of XMLand JavaScripts.The Java Script used to escalate Privilege and bypass UAC.The UAC bypass method involves hijacking the registry in HKCU\software\classes\mscfile\shell\open\command and then executing eventvwr.exe.

After decoding all the scripts it will read the following registry if it dosesn’t exists it will create them.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Seed0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Feed0

Then it looks for the network adapter configured to connect with C&C server HTTP POST to hxxp://www[.]narrowbabwe[.]net/comsary/index[.]php to connect and download the malicious payload to establish control over the machine.

Also Read Exploitation Framework for Embedded devices – RouterSploit

Solution From Fortinet

  • Apply the patches released by Microsoft in April that covers the CVE-2017-0199 vulnerability.
  • FortiGuard Antivirus service detects this threat as
  • MSOffice/Downloader!exploit.CVE20170199
  • FortiGuard Web Filtering service blocks all C&C and related URLs.
  • FortiSandbox rates the PPSX file as High Risk.

https://www.youtube.com/watch?v=zpfNf8JTSQM

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...

Meta Removed 2 Million Account Linked to Malicious Activities

 Meta has announced the removal of over 2 million accounts connected to malicious activities,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

7-Zip RCE Vulnerability Let Attackers Execute Remote Code

A critical security vulnerability has been disclosed in the popular file archiving tool 7-Zip,...

Helldown Ransomware Attacking VMware ESXi And Linux Servers

Helldown, a new ransomware group, actively exploits vulnerabilities to breach networks, as since August...

Volt Typhoon Attacking U.S. Critical Infra To Maintain Persistent Access

Volt Typhoon, a Chinese state-sponsored threat actor, targets critical infrastructure sectors like communications, energy,...