Thursday, January 30, 2025
HomeCVE/vulnerabilityPowerPoint file Equipped with CVE-2017-0199 could Compromise Your System

PowerPoint file Equipped with CVE-2017-0199 could Compromise Your System

Published on

SIEM as a Service

Follow Us on Google News

Security experts from FortiGuard Labs discovered a malicious Powerpoint file in name ADVANCED DIPLOMATIC PROTOCOL AND ETIQUETTE SUMMIT.ppsx using the CVE-2017-0199 Vulnerability.By opening, this malicious PDF file may compromise your system.

CVE-2017-0199 was originally a zero-day remote code execution vulnerability that allowed attackers to use a flaw that exists within the Windows Object Linking and Embedding (OLE) interface of Microsoft workplace to deliver malware.

This vulnerability has been disclosed and patched in last April 2017. This vulnerability triggers an RCE with Microsoft Office or Word with specially crafted files.

Fortigate identified that the flaw is used by attackers in Windows Object Linking and Embedding (OLE) interface of Microsoft Office and gain control over the system.

Powerpoint Malware
Source : Fortinet

When the malicious file opened by the user it triggers ppt/slides/_rels/slide1.xml.rels and then it use to download remote code from hxxp://www[.]narrowbabwe[.]net:3345/exp[.]doc.The remote code developers include blank spaces to evade malware detection.

Also Read Exploit Windows Remote PC with EternalBlue & DoublePulsar Exploit through Metasploit

They observed that exploit to use to download the doc file and it consist of XMLand JavaScripts.The Java Script used to escalate Privilege and bypass UAC.The UAC bypass method involves hijacking the registry in HKCU\software\classes\mscfile\shell\open\command and then executing eventvwr.exe.

After decoding all the scripts it will read the following registry if it dosesn’t exists it will create them.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Seed0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Feed0

Then it looks for the network adapter configured to connect with C&C server HTTP POST to hxxp://www[.]narrowbabwe[.]net/comsary/index[.]php to connect and download the malicious payload to establish control over the machine.

Also Read Exploitation Framework for Embedded devices – RouterSploit

Solution From Fortinet

  • Apply the patches released by Microsoft in April that covers the CVE-2017-0199 vulnerability.
  • FortiGuard Antivirus service detects this threat as
  • MSOffice/Downloader!exploit.CVE20170199
  • FortiGuard Web Filtering service blocks all C&C and related URLs.
  • FortiSandbox rates the PPSX file as High Risk.

https://www.youtube.com/watch?v=zpfNf8JTSQM

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

10,000 WordPress Websites Hacked to Distributing MacOS and Microsoft Malware

Over 10,000 WordPress websites have been hijacked to deliver malicious software targeting both macOS...

New RDP Exploit Allows Attackers to Take Over Windows and Browser Sessions

Cybersecurity experts have uncovered a new exploit leveraging the widely used Remote Desktop Protocol...

New SMS-Based Phishing Tool ‘DevilTraff’ Enables Mass Cyber Attacks

Cybersecurity experts are sounding the alarm about a new SMS-based phishing tool, Devil-Traff, that...

DeepSeek Database Publicly Exposed Sensitive Information, Secret Keys & Logs

Experts at Wiz Research have identified a publicly exposed ClickHouse database belonging to DeepSeek,...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Windows CLFS Buffer Overflow Vulnerability CVE-2024-49138 – PoC Released

 A recently disclosed Windows kernel-level vulnerability, identified as CVE-2024-49138, has raised significant security concerns in...

Zyxel CPE Zero-Day (CVE-2024-40891) Exploited in the Wild

Security researchers have raised alarms about active exploitation attempts targeting a newly discovered zero-day...

Windows 11 24H2 Update Bug: Users Report Disruptions in Web Camera and USB Devices

Windows 11 KB5050009 for version 24H2 has sparked widespread frustrations among users due to...