Vulnerabilities in Microsoft 365 Apps
ID: 69af4137-d032-5696-85d4-a55c77d2f19a
STIX ID: report--69af4137-d032-5696-85d4-a55c77d2f19a
Feed Name: Zscaler Security Research Blog
This report details reverse engineering of Microsoft 365's MSOSPECTRE.DLL (Office 3D) and the creation of SketchUp and FreeImage fuzzing harnesses, which uncovered numerous serious vulnerabilities (including use-after-free, heap/stack buffer overflows, integer overflows, out-of-bounds writes, and type confusion). It explains the SKP file formats (MFC and VFF), outlines the parsing call flow and SketchUp/FreeImage APIs used, describes the fuzzing workflow and sample minimization, and shows how crafted image files were embedded into SKP templates to reproduce crashes and PoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
