Microsoft: Unpatched Office zero-day [CVE-2023-36884]
ID: 8d1c447d-49b6-593e-8463-f5f4fdce9171
STIX ID: report--8d1c447d-49b6-593e-8463-f5f4fdce9171
Feed Name: ThreatLocker Blog
Microsoft disclosed CVE-2023-36884, a remote code execution vulnerability in Windows and Office that can be exploited by crafted Office documents which execute code even with macros disabled or in Protected View; attackers use this to install the RomCom backdoor (delivered as Calc.exe and persisted as security.dll) that registers to a C2, exfiltrates system information, and accepts commands. The report lists affected Office executables and recommends mitigations including blocking Office from creating child processes (Defender for Office or a registry key) and highlights ThreatLocker's ringfencing as a preventative control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
