Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Cobalt payload exploiting CVE-2017-11882

released on 2017-11-23 @ 05:15:18 PM
A 17-year-old vulnerability in Microsoft Office Equation Editor is now confirmed to be exploited by the Cobalt Group. Seeing that Microsoft Office is the world's most widely used office suite, vulnerabilities found in its components present a major security issue. The risk is even greater with remote code execution vulnerabilities, as the attacker does not need physical access to take control of the affected system. One such vulnerability is CVE-2017-11882, discovered in Microsoft Office Equation Editor, the application for creating math and science equations within Office documents. The memory-corruption issue has been present in the Microsoft Office code for 17 years - not even the latest Windows 10 Creators Update was spared.