What you need to know about the Microsoft Office zero-day Word threat.

Need Help Right Now?

Click Here

There is a new threat on the horizon for all Microsoft® Office users. A new zero-day attack that installs malware onto fully patched systems running Microsoft’s operating system via an Office vulnerability.

Ransomware

We recommend refraining from sending or opening any Word documents via email. Microsoft Office has a feature called “Protected View” that is enabled by default; however, you should double check your settings to make sure that this feature is turned on. If you do open a Word document and see this pop-up, it’s a pretty good indicator that something is wrong.

In addition to being highly suspicious of any Word document that arrives in an email, there are a few other things we’d recommend that you consider:

  • Warn your users, and let them know of the heightened risk related to this attack right now, so they’ll be better prepared if they receive an email with one of these attachments.
  • Consider sharing documents through SecuriSync® instead, which can mitigate the risk.
  • Within your email filtering solution, such as Intermedia Email Protection, consider temporarily putting a policy in place to block Word documents, just until Microsoft releases the patch.

If you are managing your systems with Active Directory®, consider temporarily enabling the Group Policy Object (GPO) that disallows editing of flagged files. This means users will just have a read-only protected view for any documents that Microsoft recognizes as unsafe. Within Trust Center, enable the GPO that uses File Block to block .rtf files, not even allowing for them to be opened in “Protected View.”

Microsoft has released a fix.  If you auto update your system or if you have an MSP handling your business then this patch should be installed.

Alexssa

“Daniel and the people in his company are some of the most knowledgeable I have come across in the field. Additionally, they are responsive, do what they say, when they say, and proactively communicate, so you know what the problem is, what it will take to fix it, what it will cost and who in your company it will impact. Their solutions work the first time and are cost-effective.”

Proactively Communicate   Proactively Communicate