Mitre, Microsoft differ on how severe MS Office flaw really is
- by nlqip
In a security advisory last updated on Saturday, Microsoft gave the flaw “Exploitation Less Likely” status, which it defines in part as follows: “ Microsoft analysis has shown that while exploit code could be created, an attacker would likely have difficulty creating the code, requiring expertise and/or sophisticated timing, and/or varied results when targeting the affected product. Moreover, Microsoft has not recently observed a trend of this type of vulnerability being actively exploited in the wild. This makes it a less attractive target for attackers.”
Mitre, on the other hand, states in its analysis that the likelihood of an exploitation from the exposure of NTLM hashes is high, and that information exposures can occur in different ways, key among them being “the code manages resources that intentionally contain sensitive information, but the resources are unintentionally made accessible.”
The analysis notes that sensitive information could include personal information such as health records, business secrets and intellectual property, network status and configuration, and “system status and environment, such as the operating system and installed packages.”
Source link
lol
In a security advisory last updated on Saturday, Microsoft gave the flaw “Exploitation Less Likely” status, which it defines in part as follows: “ Microsoft analysis has shown that while exploit code could be created, an attacker would likely have difficulty creating the code, requiring expertise and/or sophisticated timing, and/or varied results when targeting the…
Recent Posts
- Hackers abuse Avast anti-rootkit driver to disable defenses
- Microsoft testing Windows 11 support for third-party passkeys
- Windows 11 24H2 update blocked on PCs with Assassin’s Creed, Star Wars Outlaws
- Windows 10 KB5046714 update fixes bug preventing app uninstalls
- Eight Key Takeaways From Kyndryl’s First Investor Day