Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums
ID: 70e62743-f6e5-5911-b583-d81d299d7269
STIX ID: report--70e62743-f6e5-5911-b583-d81d299d7269
Feed Name: cybersecurityNews.com
A Russian-language underground forum vendor identified as "Zeroplayer" is advertising a Microsoft Office zero-day RCE combined with a sandbox escape for $30,000, claiming compatibility with recent Office/Windows updates and the ability to achieve full system compromise via malicious documents; no public evidence of in-the-wild exploitation is provided. Organizations are advised to harden Office configurations (disable macros, enable Protected View), deploy advanced threat protections, monitor for forum activity and indicators, and apply any Microsoft fixes promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
