<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Office Archives - Henocon Limited</title>
	<atom:link href="https://www.henocon.ie/tag/office/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.henocon.ie/tag/office/</link>
	<description>We specialise in Security Vulnerability Identification and Hacking Attack Methods in business IT systems.</description>
	<lastBuildDate>Wed, 01 Jun 2022 12:23:01 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.henocon.ie/wp-content/uploads/2016/09/cropped-favicon-site-32x32.png</url>
	<title>Office Archives - Henocon Limited</title>
	<link>https://www.henocon.ie/tag/office/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Zero Day Vulnerability identified in Office Products</title>
		<link>https://www.henocon.ie/vulnerability-identified-in-office-products/</link>
		
		<dc:creator><![CDATA[Ed Heneghan]]></dc:creator>
		<pubDate>Wed, 01 Jun 2022 12:23:00 +0000</pubDate>
				<category><![CDATA[IT System Security]]></category>
		<category><![CDATA[Office]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.henocon.ie/?p=13850</guid>

					<description><![CDATA[<p>Vulnerability in Microsoft Office products, called &#8220;Follina&#8221;, that bypasses many of the built-in security protections found. This vulnerability leverages the Microsoft Diagnostic tool to execute code on an affected machine, and can bypass the usual protections in place to prevent. The user doesn&#8217;t even need to be an administrator! More detail can be found here: [&#8230;]</p>
<p>The post <a href="https://www.henocon.ie/vulnerability-identified-in-office-products/">Zero Day Vulnerability identified in Office Products</a> appeared first on <a href="https://www.henocon.ie">Henocon Limited</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Vulnerability in Microsoft Office products, called &#8220;Follina&#8221;, that bypasses many of the built-in security protections found.</p>



<p>This vulnerability leverages the Microsoft Diagnostic tool to execute code on an affected machine, and can bypass the usual protections in place to prevent. The user doesn&#8217;t even need to be an administrator! More detail can be found here: <a href="https://www.theregister.com/2022/05/30/follina_microsoft_office_vulnerability/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2022/05/30/follina_microsoft_office_vulnerability/</a></p>



<p>The chain of events leading to this is as follows:</p>



<ul class="wp-block-list"><li>User receives a loaded email with the bogus document</li><li>The document contains a call which initiates the Microsoft Diagnostic tool when opened</li><li>The diagnostic tool spawns a child process which can then execute the code on a user&#8217;s machine (usually a PowerShell script)</li><li>This will execute even with macros disabled!</li><li>While the code is run under the user account that opened the document, this opens up another attack path for a malicious actor to elevate privilege.</li></ul>



<p>This is a pretty nasty vulnerability that couldn&#8217;t necessarily be prevented by general security hygiene. However, an organisation&#8217;s response to this can make all the difference when it comes to your exposure.  </p>



<p>If you want to see how Henocon can help with your cybersecurity incident readiness, you can reach out to us <a href="https://www.henocon.ie/contact-henocon/" rel="nofollow">here</a></p>



<p><br><br> </p>
<p>The post <a href="https://www.henocon.ie/vulnerability-identified-in-office-products/">Zero Day Vulnerability identified in Office Products</a> appeared first on <a href="https://www.henocon.ie">Henocon Limited</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
