Kevin Beaumont · @GossiTheDog
26194 followers · 918 posts · Server cyberplace.social

Haven't seen any working exploitation of at all - all just people reusing the crash POC, nobody made it to RCE.

#cve202321716

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
25027 followers · 841 posts · Server cyberplace.social

Still no working samples

#cve202321716

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
24911 followers · 847 posts · Server cyberplace.social

Continuing to keep an eye on with custom rules in - pleased to say after a week of people trying, I haven't seen anybody who has actually made it to RCE yet (or even close).

#cve202321716 #virustotal

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
24820 followers · 817 posts · Server cyberplace.social

I've been keeping an eye on (the MS Word RTF vuln) via

The headline is, people are starting to experiment with it.

#cve202321716 #gossimonitoring

Last updated 2 years ago

Joe Shenouda · @shenouda
114 followers · 103 posts · Server cybersecurity.masto.host

Looks like Microsoft Word just got a new RCE vulnerability patched... don't worry, we'll just stick to carrier pigeons for sharing documents from now on 🐦 cybersec.xmcyber.com/s/microso

#cve202321716 #MicrosoftWord

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
24774 followers · 806 posts · Server cyberplace.social

Keep an eye on CVE-2023-21716 aka MS Word vulnerability from February 2023 in RTF files.

There's a public proof of concept: qoop.org/publications/cve-2023

Where it gets more interesting - you can embed RTF files in email, Microsoft Outlook renders them with no clicks, by just reading the email.

#cve202321716

Last updated 2 years ago