<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="margin:0px;font-size:12pt;color:black;background-color:rgb(255, 255, 255)"><span style="margin:0px;background-color:white"><span style="margin:0px;font-size:14.67px">Hello,</span></span></span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<div style="margin:0px;font-size:12pt;color:black;background-color:rgb(255, 255, 255)">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black"><span style="margin:0px;background-color:white"></span>
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black"><span style="margin:0px;background-color:white"></span>
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:14.67px;background-color:white">I hope everyone is doing well!</div>
<div style="margin:0px;font-size:14.67px;background-color:white"><br>
</div>
<div style="margin:0px;font-size:14.67px;background-color:white">Below is the entry for today.</div>
<div style="margin:0px;font-size:14.67px;background-color:white"><br>
</div>
<div style="margin:0px;font-size:14.67px;background-color:white">08/25/2021 - Diary entry #334<br>
<br>
</div>
<blockquote style="font-size:14.67px;background-color:white;margin-top:0px;margin-bottom:0px">
<div style="margin:0px"></div>
<div style="margin:0px"></div>
Today we are going to talk about Microsoft Office documents as an infection vector. It's not uncommon to receive spam messages with Office documents attached. Word documents, PowerPoints, Spreadsheets, all the common file formats can be used to deliver a phishing
 link or a malware.
<div><br>
</div>
<div>Since MS Office 97, that introduced the macro programing language Visual Basic for Applications (or VBA), attackers have found creative ways to abuse it and execute malicious commands in users' machines. With the evolution of MS Office, new vulnerabilities
 have been found and fixed. As it's a very popular tool, attackers and researchers are constantly trying to find new vulnerabilities that can be exploited.</div>
<div><br>
</div>
<div>The problem with MS Office is that it's very common to find users with an older version (and therefore vulnerable) installed. Even nowadays CVE-2017-11882, a memory corruption issue in MS Office that affected multiple versions from MS Office 2007 to MS
 Office 2013, is still heavily used by families like Agent Tesla (covered in our Daily Diary #92), LokiBot, and many others. That shows how common it is for users to have very old versions of MS Office installed.</div>
<div><br>
</div>
Companies should be aware that using old versions of MS Office is a huge security risk, and they should train employees to never open this kind of attachments in e-mails from unknown senders. One option that many institutions adopted nowadays is to use Office365,
 the cloud-version of the suite. Using Office365 mitigates most risks involved macros and memory corruption vulnerabilities, but documents can still be used as part of a social engineering attack, convincing users to access a malicious link or download an attachment.
<div style="margin:0px"></div>
<span style="margin:0px"></span>
<div style="margin:0px"></div>
<span style="margin:0px"></span>
<div style="margin:0px"></div>
<span style="margin:0px"></span>
<div style="margin:0px"></div>
<span style="margin:0px"></span>
<div style="margin:0px"></div>
<span style="margin:0px"></span>
<div style="margin:0px"><br>
</div>
</blockquote>
<span style="margin:0px;font-size:14.67px;background-color:white">Kind Regards,</span></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div></div>
<div></div>
<div></div>
<div></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<table style="font-family:"Times New Roman"; font-size:medium; text-align:start">
<tbody>
<tr>
<td width="180" align="left" style="width:180px">
<table width="120" align="left">
<tbody>
<tr>
<td colspan="3" align="center"><a href="https://www.appgate.com/"><img alt="" width="120" height="30" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/logo@2x.png"></a></td>
</tr>
<tr>
<td colspan="3" align="center"> </td>
</tr>
<tr>
<td width="37%" align="center"><a href="https://www.linkedin.com/company/appgate-security/"><img width="18" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/likedin@2x.png"></a></td>
<td width="28%"><a href="https://twitter.com/AppgateSecurity"><img width="20" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/twitter@2x.png"></a></td>
<td width="35%"><a href="https://www.youtube.com/channel/UC-8GvxcZbm-R3EJNl8jYjiQ"><img width="26" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/youtube@2x.png"></a></td>
</tr>
</tbody>
</table>
<p> </p>
</td>
<td width="350" colspan="2" rowspan="2" style="width:350px">
<p style="font-family:Arial,Helvetica,sans-serif; font-size:13px; color:rgb(12,12,12)">
<strong>Felipe Duarte Domingues</strong><br>
Security Researcher<br>
<strong>Appgate</strong></p>
<p style="font-family:Arial,Helvetica,sans-serif; font-size:13px; color:rgb(12,12,12)">
E:<span> </span><font color="#228ebe"><a href="mailto:felipe.duarte@appgate.com" title="mailto:felipe.duarte@appgate.com">felipe.duarte@appgate.com</a></font><br>
O: <span style="background-color:rgb(255,255,255); display:inline!important">+55 19 98840 2509</span></p>
</td>
</tr>
</tbody>
</table>
<br>
</div>
</div>
</div>
</div>
</body>
</html>