Hackers have revived a decade-old Microsoft Office exploit - and they’re having a field day

(Image credit: Shutterstock)

Hackers have ramped up attempts to abuse a decade-old Microsoft Office flaw with the help of creative new email scams, new research has found. 

According to analysis commissioned by NordVPN, attempts to exploit the vulnerability (CVE-2017-11882) rose by 400% in the second quarter of the year - with further growth expected.

If exploited successfully, the memory corruption bug could allow attackers to execute code on the target device remotely. This is especially problematic if the affected user account has administrative privileges, in which scenario the hacker could seize control of the system.

Once inside, a malicious actor could install programs at will, access and delete data, and create new accounts with full access rights.

Microsoft Office vulnerability

According to the Microsoft Security listing, to abuse the vulnerability hackers must trick targets into opening a specially crafted file containing an infected copy of Microsoft Office or Microsoft WordPad.

The most common and effective means of distributing these infected files is via email phishing campaigns, many of which are highly convincing and manipulative.

For example, the US Secret Service (USSS) warned citizens of an email scam in April, at the height of the pandemic, that attempted to lure victims into opening an attachment that claimed to contain important coronavirus information.

By preying on human insecurities and attaching scams to macro world events, hackers are able to infect a large pool of victims with relative ease.

“The malware targeting a decade-old MS Office vulnerability must have been under the radar, as it has been spreading through emails for three years now,” explained Daniel Markuson, Digital Privacy Expert at NordVPN.

According to the firm, businesses are at heightened risk of this form of attack, as a result of the value of data held in corporate networks and also because of the fallibility of employees.

“When internal corporate systems get breached, 99% of cases are caused by employees. The most popular way to lure employees into the trap is by email,” added Markuson.

“Businesses must stay alert and should employ defence-in-depth tactics and equip themselves with multi-layered security mechanisms, including high-sensor spam filters and a VPN connection, which would prevent malicious pages from opening.”

Individual users, meanwhile, are advised to scrutinize emails for abnormalities that might identify a scam (such as spelling errors) and ensure the sender address appears regular.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day