Thursday, November 21, 2024
More
    Business & FinanceUnveiling the Hidden Dangers: Discover the Surprising Security Flaws...

    Unveiling the Hidden Dangers: Discover the Surprising Security Flaws in Microsoft 365 Apps

    -

    - Advertisment -spot_img

    Microsoft 365 Vulnerabilities Discovered

    A team of cybersecurity researchers from Zscaler has uncovered over a hundred vulnerabilities in Microsoft 365. These vulnerabilities were introduced with the integration of SketchUp into the cloud productivity suite. What’s even more concerning is that the researchers claim to have bypassed the patches released by Microsoft to address these flaws.

    The Impact of SketchUp Integration

    SketchUp is a program that allows users to add 3D models to Microsoft documents. It was first introduced in August 2000 and later integrated into Microsoft 365’s Office 3D component. By reverse engineering the Office 3D components, the researchers discovered a total of 117 vulnerabilities in Microsoft 365 apps. These vulnerabilities are attributed to the support for SketchUp 3D files (SKP) and include heap buffer overflow, out-of-bounds write, and stack buffer overflow vulnerabilities.

    Bypassed Solutions

    Microsoft categorized these vulnerabilities as “remote code execution” (RCE) and grouped them into three CVEs: CVE-2023-28285, CVE-2023-29344, and CVE-2023-33146. All three are labeled as “high severity” with a severity score of 7.8. Zscaler’s senior principal security researcher, Kai Lu, stated that there is currently no evidence of these vulnerabilities being exploited in the wild. However, he emphasized that skilled threat actors could potentially discover and weaponize these vulnerabilities at any time.

    - Advertisement -
    Top Homepage Banner Advertise With Us 30%

    Microsoft’s Response

    Microsoft temporarily disabled support for SketchUp after the researchers managed to bypass the patches. The company created a patch to address the vulnerabilities but did not provide further details. Microsoft assured its customers that they have been protected since June when the SketchUp feature was temporarily disabled. Customers are advised to check SketchUp’s status on Microsoft’s dedicated page for updates.

    Conclusion

    While the vulnerabilities discovered by Zscaler have not been exploited yet, the potential for skilled threat actors to weaponize them remains a concern. Microsoft’s swift response in disabling SketchUp support and releasing patches demonstrates their commitment to addressing these vulnerabilities. It is crucial for Microsoft 365 users to stay updated with the latest security measures and patches to ensure the protection of their data and systems.

    Photo: Freepik.com

    - Advertisement -
    Top Homepage Banner Advertise With Us 30%
    Matthew Harrison
    Matthew Harrison
    Meet Matthew Harrison, a prominent 34-year-old sociologist hailing from Vancouver, with roots in a family of writers. Matthew's rich academic background is complemented by his literary lineage, providing him with a unique perspective on the world. Vancouver, the picturesque backdrop to his life, serves as a constant source of inspiration.Matthew's academic journey delves deep into the realm of sociological research. He boasts an extensive stint on a project investigating the impact of fake news on traditional journalism. His work unravels crucial aspects of the media landscape and its influence on our society.Apart from his research, Matthew is an enthusiastic literary creator, blending analytical and creative thinking to offer thought-provoking insights to our community.Matthew's passion for sociology is balanced by his culinary prowess. In addition to dissecting social phenomena, he crafts exquisite culinary delights and frequently hosts dinner gatherings with friends, where he shares his talents around the dining table.

    LEAVE A REPLY

    Please enter your comment!
    Please enter your name here

    Latest news

    The Amayas project will change your life

    There are situations that can change the whole life, and often the person concerned cannot find a way out...
    - Advertisement -spot_img

    Decoding Major Economies: How Global Economic Trends Affect You

    In today's rapidly changing global economy, it's essential to stay informed about the major economic trends that can affect...

    Plant Based Travel Exploring Vegan and Vegetarian Friendly Destinations

    Are you a vegan looking for your next travel adventure? Look no further! In this blog post, I will...

    Must read

    The Unseen Side of Paris: A Week of Surprises Beyond the Typical Tourist Trail

    Embark on a weeklong journey through the enchanting streets...
    - Advertisement -spot_img

    USA Winter Wonderland: 10 Destinations for the Ultimate Seasonal Escape

    Embarking on a winter journey across the United States and its neighboring havens promises a symphony of diverse experiences,...

    The Sweet Deception: Unveiling the Hidden Secrets of Low-Calorie Sugar Substitutes

    Finding Healthier Alternatives to Sugar Low-calorie sweeteners like aspartame have become a common addition to our diets. However, concerns about...
    - Advertisement -spot_img

    You might also likeRELATED
    Recommended to you