Microsoft has been vigorously promoting Microsoft Office applications, allowing users to use classic suites of productivity tools, and continues to add a variety of new features that keep pace with the times. Recently, Microsoft revealed a zero-day vulnerability of the highest severity, affecting multiple Office and 365 products. Attackers may use this vulnerability to steal private information from individuals or organizations. As for the fix update, it should be released around 8/13.

Microsoft reveals unpatched high-severity vulnerability in Microsoft Office applications
The vulnerability number is CVE-2024-38200(If you are interested, click here to view more details.) Also known as the “Microsoft Office Spoofing Vulnerability”, the attacker does not need to spend much effort to induce the victim to open malicious files or execute undesirable programs. He only needs to guide the respondent to visit a website containing a “specially crafted file”. It is a vulnerability with high risk and relatively easy to exploit.

The Offiice series products listed below are all affected by CVE-2024-38200:
- Microsoft Office 2016 (32-bit and 64-bit)
- Microsoft Office 2016 (32-bit and 64-bit)
- Microsoft Office LTSC 2021 (32-bit and 64-bit)
- Microsoft 365 enterprise apps (32-bit and 64-bit)
MITRE It is possible that an attacker could exploit this vulnerability. For its part, Microsoft marked the exploit as “unlikely,” which means a patch should be available before attackers can figure out how to build the malicious profiles required for exploitation, but keep in mind that regardless, individuals or organizations that fail to install the required security updates will be more at risk.

Users of affected versions of Microsoft Office should, as always, avoid opening unknown websites (especially URLs shared via email). Organizations and enterprises can take more proactive measures to reduce risks. Microsoft recommends adding sensitive users to protected user security groups. Blocking TCP 445/SMB in firewall and VPN settings can also reduce potential exposure, and both changes can be undone after installing Microsoft’s security fixes, which are tentatively scheduled for August 13.
Source: KOCPC Chinese