Trojan leverages patched Microsoft Office flaw

By

The exploit arrives as an email.

Researchers at Symantec said they have spotted a trojan taking advantage of a previously patched Microsoft Office vulnerability.

Trojan leverages patched Microsoft Office flaw

The exploit, which is being used in targeted attacks, arrives as an email that contains a Microsoft Word file and a separate DLL file, a rare combination considering DLL files are not typically sent over email.

"The exploit makes use of an ActiveX control embedded in the Word document file," senior researcher Joji Hamada wrote Thursday in a blog post. "When the Word document is opened, the ActiveX control calls fputlsat.dll, which has the identical file name as the legitimate DLL file used for the Microsoft Office FrontPage Client Utility LIbrary. If the exploit is successful, malware is dropped onto the system."

The trojan, dubbed "Activehijack" by Symantec, takes advantage of a vulnerability rated "important" that was patched by Microsoft in September with bulletin MS11-073.

To avoid the exploit, users should ensure they have installed the patch and remain wary of emails that contain DLL files, Hamada said.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

"Scattered Spider" evolves with new ransomware and social engineering tactics

"Scattered Spider" evolves with new ransomware and social engineering tactics

AI coding threatens to make common security flaw more prevalent

AI coding threatens to make common security flaw more prevalent

Nvidia says its chips have no 'backdoors'

Nvidia says its chips have no 'backdoors'

Russia's FSB conducts ISP-level cyber espionage, Microsoft says

Russia's FSB conducts ISP-level cyber espionage, Microsoft says

Log In

  |  Forgot your password?