Microsoft Office/Wordpad Remote Code Execution via URL Moniker

Strike ID:
E17-0bfb8
CVSS:
7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
64
Year:
2017

Description

This strike exploits a vulnerability in the way Microsoft Office and Wordpad handles linked URL Moniker OLE objects. The vulnerability gives the attacker remote code execution through MSHTA.exe by forcing the response headers to be of type "application/hta." An attacker may exploit this vulnerability by enticing a user to open a specifically crafted RTF document via email or other methods.

CVE

References

Bid