Announcement: Cythera has joined forces with Bastion Security Group. Learn more
08 Jun / 2022
Cyber Security
What Is Vulnerable?
Windows Office 2013 and later, including the latest patches for Office 2021
What’s Happening?
Microsoft Office is the latest victim to a remote code execution vulnerability which was publicly disclosed by Microsoft on the 31st of May. Nicknamed Follina, this vulnerability is actively being used against Australian organisations by threat actors, according to the ACSC.
How It Works
This vulnerability harnesses Microsoft Support Diagnostic Tool (MSDT) and a malicious URL baked into a word document. When the URL is clicked HTML will download from a webserver and execute arbitrary PowerShell code using the ms-msdt protocol. There are 3 key factors that cause Follina to be troubling to security researchers.
As of the 1st of June, there are no official patches available for vulnerable versions of Office products. There is however a simple fix to remediate against this in the interim. The MSDT URI can be disabled via a registry edit in CMD or Group Policy.
Cythera continues to monitor all managed clients and detection capabilities we have in place will likely detect any post-exploitation activities related to this vulnerability.
Broadcom VMware Hypervisor Vulnerability CVE-2024-37085 - Exploited In The Wild By Ransomware Crews
Broadcom VMware Hypervisor VulnerabilityCVE: CVE-2024-37085What Is Vulnerable?Broadcom VMware ESXiVMware Cloud FoundationThe following VMWare pr…
Read MoreDon’t Fall for the ‘Tick + Flick’ Trap: The difference between a true MDR and Tick + Flick Service
An objection some customers have when we first connect is that they “already use a Managed Detection and Response service”, yet a little dig…
Read MoreCythera’s Board Advisory Service: Briefing your board on cybersecurity obligations in under 2 hours
In the face of rising cyber threats, the role of board members in safeguarding an organisation's digital assets and information has never been m…
Read More