Microsoft Office DLL Hijacking Exploit (MS15-132)
ID: 86859798-9b1a-57b9-9e99-1d1e62e0a04d
STIX ID: report--86859798-9b1a-57b9-9e99-1d1e62e0a04d
Feed Name: NCC Research
This report details DLL hijacking vulnerabilities in Microsoft Office (disclosed around MS15-132) that allow remote code execution by abusing how Office loads embedded OLE/COM objects; it demonstrates attack chains that combine Office's temp-file dropping and browser download behaviors (Firefox "Open With" and Chrome/Edge auto-download) to place and load attacker-controlled DLLs from the user's %TEMP% or Downloads folder, provides proof-of-concept techniques and mitigations, and links to patches and prior research.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
