XCLUB-COOL STUFF AROUND YOU

 找回密码
 Register
查看: 58|回复: 2
打印 上一主题 下一主题

Hackers Can Abuse Microsoft Excel Power Query For Malware Attacks

[复制链接]

9356

主题

3万

帖子

4万

积分

Jade Diamond LV39

Daily Check-inHappy children's dayHot PartyPOP OUTACTIVE STAR4.0xclubpost star1post star2sign star1sign star2sign star3post star3post star4post star5sign star4X'Club badge exclusive for India

跳转到指定楼层
#1
发表于 2019-07-01 23:07:28 来自手机 | 只看该作者 |只看大图 回帖奖励 |倒序浏览 |阅读模式
Researchers have found a way to abuse Microsoft Excel for malware attacks. The strategy involves exploiting the Microsoft Excel Power Query feature to wage Dynamic Data Exchange (DDE) attacks and deliver malware. At present, no fix is available to patch the flaw.[br][br]Microsoft Excel Power Query Abuse[br][br]Researchers at Mimecast have reported a possible technique to abuse Microsoft Excel Power Query feature. [a href="https://support.office.com/en-us/article/power-query-overview-and-learning-ed614c81-4b00-4291-bd3a-55d80767f81d"]Power Query[/a] is a scalable tool available as a separate add-on for older Microsoft Excel versions. Whereas, the modern Excel versions have this tool as a built-in feature. Power Query allows users to integrate various data sources with spreadsheets and dynamically download data for analysis. As described by Microsoft, "Power Query is a data connection technology that enables you to discover, connect, combine, and refine data sources to meet your analysis needs… With Power Query, you can search for data sources, make connections, and then shape that data (for example remove a column, change a data type, or merge tables) in ways that meet your needs"[br][br]According to the researchers, a potential attacker can abuse this feature for delivering malware by embedding malicious codes to a datasheet. Upon opening the datasheet, the malicious code would run on the target system executing the malware. According to their blog spot, [br]"Such attacks are usually hard to detect and gives threat actors more chances to compromise the victim’s host. Using the potential weakness in Power Query, attackers could potentially embed any malicious payload that as designed won’t be saved inside the document itself but downloaded from the web when the document is opened."[br][br]They also demonstrated a DDE exploit abusing Power Query for which they have shared the details in their blog post.[br][br]Microsoft Recommends A Workaround – No Fix Yet[br][br]Upon finding a successful exploit technique, Mimecast reached out to Microsoft to report the matter. Nonetheless, Microsoft, according to the researchers, said their was no fix.[br][br]However, they advised a workaround to mitigate the attack. In a recent advisory, Microsoft has explained how users can safely open Microsoft Documents (both Excel and Word files) containing the DDE field.[br][br]Source: https://latesthackingnews.com/2019/07/01/hackers-can-abuse-microsoft-excel-power-query-for-malware-attacks/
Never give up
回复

使用道具 举报

5736

主题

2万

帖子

3万

积分

Jade Diamond LV36

ACTIVE STAR2019post star1post star2sign star1sign star2sign star3post star3post star4post star5sign star4X'Club badge exclusive for India

#2
发表于 2019-07-02 00:19:22 来自手机 | 只看该作者
thanks again for the information
回复

使用道具 举报

1712

主题

1万

帖子

2万

积分

Golden Star LV30

Happy children's dayDiamondsign star1sign star2sign star3post star1post star2post star3post star4sign star4X'Club badge exclusive for India

#3
发表于 2019-07-02 01:03:31 来自手机 | 只看该作者
nice info .
回复

使用道具 举报

高级模式
B Color Link Quote Code Smilies |上传

本版积分规则

Infinix Official Website|Infinix official mall|infinix Note 4|XCLUB-COOL STUFF AROUND YOU

GMT+8, 2025-01-12 19:02 , Processed in 0.034209 second(s), 20 queries .

Powered by Discuz! X3.4

© 2001-2017 Comsenz Inc.

快速回复 返回顶部 返回列表