Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. The Insider News
  4. Microsoft warns of unpatched Office vulnerability leading to data exposure

Microsoft warns of unpatched Office vulnerability leading to data exposure

Scheduled Pinned Locked Moved The Insider News
htmlcomquestionannouncement
5 Posts 4 Posters 15 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    K Offline
    Kent Sharkey
    wrote on last edited by
    #1

    The Hacker News[^]:

    Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors.

    Maybe they should save some time and warn us when Office isn't vulnerable?

    J 1 Reply Last reply
    0
    • K Kent Sharkey

      The Hacker News[^]:

      Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors.

      Maybe they should save some time and warn us when Office isn't vulnerable?

      J Offline
      J Offline
      jeron1
      wrote on last edited by
      #2

      Quote:

      However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file

      1-in-3 Click Suspicious Links & 1-in-5 Email Attacks Succeed[^] The 'convincing' part seems to be the easiest part. :(

      "the debugger doesn't tell me anything because this code compiles just fine" - random QA comment "Facebook is where you tell lies to your friends. Twitter is where you tell the truth to strangers." - chriselst "I don't drink any more... then again, I don't drink any less." - Mike Mullikins uncle

      D Richard DeemingR 2 Replies Last reply
      0
      • J jeron1

        Quote:

        However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file

        1-in-3 Click Suspicious Links & 1-in-5 Email Attacks Succeed[^] The 'convincing' part seems to be the easiest part. :(

        "the debugger doesn't tell me anything because this code compiles just fine" - random QA comment "Facebook is where you tell lies to your friends. Twitter is where you tell the truth to strangers." - chriselst "I don't drink any more... then again, I don't drink any less." - Mike Mullikins uncle

        D Offline
        D Offline
        David ONeil
        wrote on last edited by
        #3

        jeron1 wrote:

        However, an attacker would have no way to force the user to visit the website.

        Maybe Copilot can be used for that? If AI can't make letting hackers in easier, what is it good for?

        Our Forgotten Astronomy | Object Oriented Programming with C++ | Wordle solver

        J 1 Reply Last reply
        0
        • J jeron1

          Quote:

          However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file

          1-in-3 Click Suspicious Links & 1-in-5 Email Attacks Succeed[^] The 'convincing' part seems to be the easiest part. :(

          "the debugger doesn't tell me anything because this code compiles just fine" - random QA comment "Facebook is where you tell lies to your friends. Twitter is where you tell the truth to strangers." - chriselst "I don't drink any more... then again, I don't drink any less." - Mike Mullikins uncle

          Richard DeemingR Offline
          Richard DeemingR Offline
          Richard Deeming
          wrote on last edited by
          #4

          Given they've been adding exactly the same boilerplate text to virtually every security KB for at least the last two decades, I doubt they've paid any attention to studies that don't start with the assumption that the user is on a dial-up connection. :sigh: "If the computer starts screaming at you, pick up the handset of your land-line, and use the rotary dial to call the operator in order to disconnect the Internet."


          "These people looked deep within my soul and assigned me a number based on the order in which I joined." - Homer

          "These people looked deep within my soul and assigned me a number based on the order in which I joined" - Homer

          1 Reply Last reply
          0
          • D David ONeil

            jeron1 wrote:

            However, an attacker would have no way to force the user to visit the website.

            Maybe Copilot can be used for that? If AI can't make letting hackers in easier, what is it good for?

            Our Forgotten Astronomy | Object Oriented Programming with C++ | Wordle solver

            J Offline
            J Offline
            jeron1
            wrote on last edited by
            #5

            Indeed. :)

            "the debugger doesn't tell me anything because this code compiles just fine" - random QA comment "Facebook is where you tell lies to your friends. Twitter is where you tell the truth to strangers." - chriselst "I don't drink any more... then again, I don't drink any less." - Mike Mullikins uncle

            1 Reply Last reply
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups