Microsoft users on high alert over dangerous RCE zero-day | Computer Weekly
Summary
Although not deemed a critical vulnerability, the flaw’s use by a group Microsoft is tracking as Storm-0978, also known as RomCom after its backdoor malware, appears to have prompted Redmond’s security teams to take pre-emptive action. Its current lures are largely themed around Ukrainian political affairs, most notably Kyiv’s attempts to join the Nato alliance. For CVE-2023-36884 specifically, it is recommending the use of Block all Office applications from creating child processes attack surface reduction rule, or if this can’t be done, setting the FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION registry key to avoid exploitation, although doing so can cause some functionality issues. This campaign – which saw attackers gain admin privileges on compromised systems before using the drivers – may be read as a sixth zero-day, depending on whose definition of the term you subscribe to. Microsoft has been investigating this issue since being informed of it by Sophos researchers in February, with other reports from Trend Micro and Cisco Talos also assisting.