{"id":174710,"date":"2022-05-30T08:22:18","date_gmt":"2022-05-30T10:22:18","guid":{"rendered":"https:\/\/teknomers.com\/fr\/fais-attention-des-chercheurs-reperent-un-nouvel-exploit-microsoft-office-zero-day-dans-la-nature\/"},"modified":"2022-05-30T08:22:24","modified_gmt":"2022-05-30T10:22:24","slug":"fais-attention-des-chercheurs-reperent-un-nouvel-exploit-microsoft-office-zero-day-dans-la-nature","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/fais-attention-des-chercheurs-reperent-un-nouvel-exploit-microsoft-office-zero-day-dans-la-nature\/","title":{"rendered":"Fais attention!  Des chercheurs rep\u00e8rent un nouvel exploit Microsoft Office Zero-Day dans la nature"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Les chercheurs en cybers\u00e9curit\u00e9 attirent l&#8217;attention sur une faille zero-day dans Microsoft Office qui pourrait \u00eatre exploit\u00e9e pour obtenir l&#8217;ex\u00e9cution de code arbitraire sur les syst\u00e8mes Windows concern\u00e9s.<\/p>\n<p>La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9e apr\u00e8s qu&#8217;une \u00e9quipe de recherche ind\u00e9pendante sur la cybers\u00e9curit\u00e9 connue sous le nom de nao_sec a d\u00e9couvert un document Word (&#8220;<a rel=\"nofollow noopener\" href=\"https:\/\/www.virustotal.com\/gui\/file\/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784\/detection\" target=\"_blank\">05-2022-0438.doc<\/a>&#8220;) qui a \u00e9t\u00e9 t\u00e9l\u00e9charg\u00e9 sur VirusTotal \u00e0 partir d&#8217;une adresse IP en Bi\u00e9lorussie.<\/p>\n<p>&#8220;Il utilise le lien externe de Word pour charger le code HTML, puis utilise le sch\u00e9ma&#8221; ms-msdt &#8220;pour ex\u00e9cuter le code PowerShell&#8221;, ont d\u00e9clar\u00e9 les chercheurs. <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/nao_sec\/status\/1530196847679401984\" target=\"_blank\">c&#8217;est not\u00e9<\/a> dans une s\u00e9rie de tweets la semaine derni\u00e8re.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backup-github\" target=\"_blank\" title=\"DevOps backup\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/05\/Arret-de-loperation-Conti-Ransomware-apres-la-division-en-groupes.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>Selon le chercheur en s\u00e9curit\u00e9 Kevin Beaumont, qui a surnomm\u00e9 la faille &#8220;Follina&#8221;, le maldoc tire parti de Word <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/techniques\/T1221\/\" target=\"_blank\">mod\u00e8le distant<\/a> fonctionnalit\u00e9 pour r\u00e9cup\u00e9rer un fichier HTML \u00e0 partir d&#8217;un serveur, qui utilise ensuite le sch\u00e9ma d&#8217;URI &#8220;ms-msdt:\/\/&#8221; pour ex\u00e9cuter la charge utile malveillante.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/docs.microsoft.com\/en-us\/windows-server\/administration\/windows-commands\/msdt\" target=\"_blank\">MSDT<\/a> est l&#8217;abr\u00e9viation de Microsoft Support Diagnostics Tool, un utilitaire utilis\u00e9 pour d\u00e9panner et collecter des donn\u00e9es de diagnostic pour analyse par les professionnels du support technique afin de r\u00e9soudre un probl\u00e8me.<\/p>\n<p><iframe loading=\"lazy\" title=\"Maldoc .DOCX MSDT Inside Sandbox\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/GybD70_rZDs?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>&#8220;Il se passe beaucoup de choses ici, mais le premier probl\u00e8me est que Microsoft Word ex\u00e9cute le code via msdt (un outil de support) m\u00eame si les macros sont d\u00e9sactiv\u00e9es&#8221;, a d\u00e9clar\u00e9 Beaumont. <a rel=\"nofollow noopener\" href=\"https:\/\/doublepulsar.com\/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e\" target=\"_blank\">expliqu\u00e9<\/a>.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1650021915_454_Haskers-Gang-donne-gratuitement-le-logiciel-malveillant-ZingoStealer-a-dautres.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;<a rel=\"nofollow noopener\" href=\"https:\/\/support.microsoft.com\/en-us\/topic\/what-is-protected-view-d6f09ac7-e6b9-4495-8e43-2bbcdbcb6653\" target=\"_blank\">Vue prot\u00e9g\u00e9e<\/a> entre en jeu, bien que si vous modifiez le document au format RTF, il s&#8217;ex\u00e9cute sans m\u00eame ouvrir le document (via l&#8217;onglet d&#8217;aper\u00e7u dans l&#8217;Explorateur) et encore moins en mode prot\u00e9g\u00e9&#8221;, a ajout\u00e9 le chercheur.<\/p>\n<p>Plusieurs versions de Microsoft Office, y compris Office, Office 2016 et Office 2021, seraient affect\u00e9es, bien que d&#8217;autres versions soient \u00e9galement vuln\u00e9rables.<\/p>\n<p>De plus, Richard Warren de NCC Group <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/buffaloverflow\/status\/1530866518279565312\" target=\"_blank\">g\u00e9r\u00e9<\/a> pour d\u00e9montrer un exploit sur Office Professionnel Pro avec avril 2022 ex\u00e9cut\u00e9 sur une machine Windows 11 \u00e0 jour avec le volet de pr\u00e9visualisation activ\u00e9.<\/p>\n<p>&#8220;Microsoft va devoir le corriger sur toutes les diff\u00e9rentes offres de produits, et les fournisseurs de s\u00e9curit\u00e9 auront besoin d&#8217;une d\u00e9tection et d&#8217;un blocage robustes&#8221;, a d\u00e9clar\u00e9 Beaumont.  Nous avons contact\u00e9 Microsoft pour obtenir des commentaires, et nous mettrons \u00e0 jour l&#8217;histoire une fois que nous aurons r\u00e9pondu.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/05\/watch-out-researchers-spot-new.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Les chercheurs en cybers\u00e9curit\u00e9 attirent l&#8217;attention sur une faille zero-day dans Microsoft Office qui pourrait \u00eatre exploit\u00e9e pour obtenir l&#8217;ex\u00e9cution de code arbitraire sur les syst\u00e8mes Windows concern\u00e9s. La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9e apr\u00e8s qu&#8217;une \u00e9quipe de recherche ind\u00e9pendante sur la cybers\u00e9curit\u00e9 connue sous le nom de nao_sec a d\u00e9couvert un document Word (&#8220;05-2022-0438.doc&#8220;) qui [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":174711,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[2256,12848,4168,4158,4165,4161,429,133,3010,2728,4157,4159,4171,4170,4167,8362,4160,5853,716,4163,4162,4956,27258,4172,4169,4166,4164,35759],"class_list":["post-174710","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-attention","tag-chercheurs","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dans","tag-des","tag-exploit","tag-fais","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-microsoft","tag-mises-a-jour-de-la-cybersecurite","tag-nature","tag-nouvel","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-office","tag-reperent","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vulnerabilite-logicielle","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/174710","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=174710"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/174710\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/174711"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=174710"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=174710"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=174710"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}