Confirmed: Microsoft Word Vulnerability Exploited for Months
0-day

Remember that malicious document that exploited a Word vulnerability to download malware without leaving a trace? The good news is that Microsoft released its patch on April 11, 2017, and its installation is highly recommended. The bad news is that the bug was discovered in July 2016 and, over the following nine months, was used to carry out attacks in Russia, Ukraine, Australia, and Israel.

The official designation for the vulnerability is CVE-2017-0199. From a technical standpoint, it has already been fixed, and those using the most recent builds of the Office suite (from the 2007 SP3 edition onward) should be protected. However, we know very well that for various reasons, many users and administrators decide to postpone applying hotfixes. Perhaps their corporate environment is too strict, or they use illegal copies with activation systems that are neutralized through Windows Update. But bugs do not discriminate, and what would otherwise have been a routine patch turned into a nine-month odyssey.

Confirmed: Microsoft Word Vulnerability Exploited for Months

Discovery and Reporting

The story takes us back to July 2016, when security consultant Ryan Hanson discovered the 0-day. Over the next three months, he worked on the bug to assess its severity and evaluate its potential to combine with other flaws, before reporting it to Microsoft. Upon seeing the results, the folks in Redmond concluded that a quick patch would not be enough and that they couldn't share too much data about it without alerting hackers. At that time, there were no indications of the 0-day being exposed, but that changed in January of this year, which brings us to FireEye's original report. CVE-2017-0199 was used by "multiple actors" to spread at least three forms of malware, starting with FinSpy, Latentbot, and Dridex. The case of FinSpy is particularly interesting, since it is also known as FinFisher, a spyware used by dozens of governments around the world.

Attacks and Impact

The first victims were limited to Russia and Ukraine, demonstrating a certain level of precision in the campaign. After accumulating additional evidence, FireEye contacted Microsoft, but the confirmation by McAfee on April 7 essentially kicked the board, announcing the existence of the 0-day to the entire world. Two days later, the black market was already offering variants that exploited CVE-2017-0199 to distribute Dridex. The attacks shifted to Australia and other countries, with the goal of stealing funds from bank accounts. Ben-Gurion University in Israel announced that several of its employees were hacked "post-patch" by attackers linked to the Iranian government, who apparently took control of their email accounts and extended the distribution of malicious documents to more than 250 targets. The final number of affected people and the amount of money stolen remain unknown.

Beyond whether the delay might be justified, it is imperative to develop a universal platform that allows better coordination of communication between independent security researchers and corporations.

Source: Reuters