Microsoft Outlook flaw opens door to 1-click remote code execution attacks

Source
Advertisement


Microsoft released its batch of monthly security updates this month covering 73 vulnerabilities, including two zero-day flaws exploited in the wild. While organizations should prioritize all critical and high-risk issues, there is one critical vulnerability in Outlook that researchers claim could open the door to trivial attacks that result in remote code execution.

Dubbed MonikerLink by researchers from security firm Check Point Software Technologies who found it, the vulnerability allows attackers to bypass the Office Protected View mode that opens files downloaded from the internet in read-only mode by default to prevent potentially malicious scripts inside from executing.

Advertisement