logo

Having Fun with ActiveX Controls in Microsoft Word

ID: 6bea29bc-4a3b-5a0a-a62e-b93f1ce6b46a

STIX ID: report--6bea29bc-4a3b-5a0a-a62e-b93f1ce6b46a

Feed Name: Black Hills Infosec Blog

Threat Score
50/100

Date Published: 2018-08-30

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive summary:** This write-up demonstrates two practical techniques for UNC path injection in Microsoft Word using built-in ActiveX controls (Windows Media Player and ShockWave Flash) to trigger outbound SMB/WebDAV requests and capture Net-NTLM hashes, outlines observations about fallback behaviors and macro execution via ActiveX, reports disclosure to Microsoft, and recommends mitigations such as blocking outbound SMB (port 445) and disabling ActiveX via Group Policy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.