Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Contact Us
Reading: Attackers find new way to exploit Office hole patched by Microsoft
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > Cyber > Attackers find new way to exploit Office hole patched by Microsoft
Cyber

Attackers find new way to exploit Office hole patched by Microsoft

Editorial Desk
Last updated: January 3, 2022 11:54 am
Editorial Desk
Share
SHARE

Attackers have tested an exploit for a critical Office vulnerability already fixed by Microsoft.

In September 2021, Microsoft released a patch to prevent attackers from launching malicious code embedded in a Word document that downloads a Microsoft Cabinet (CAB) archive, which in turn contains a malicious executable file.

Sophos research found that the attackers reworked the original exploit by placing a malicious Word document in a specially crafted RAR archive. A new form of “no CAB” exploit attempts to bypass the original patch.

Researchers at global security company Sophos said this could indicate that a new exploit that was sent using spam for 36 hours could be reinstated at a later stage.

The original exploit affected the Office file format. To exploit this vulnerability, attackers could execute malicious code embedded in a Word document that downloads a Microsoft Cabinet archive that in turn contained a malicious executable file.

Sophos’s statement says: “The attackers rewritten the original exploit by placing a malicious Word document in a specially crafted RAR archive. A newer, “CAB-free” form of the exploit effectively bypasses the original patch.

“Sophos data shows that the amended exploit was used in the wild for around 36 hours.”

The research showed the limited lifespan of the updated attack could mean it is a “dry run” that could come back in future incidents.

Sophos Labs Research
“In theory, this attack approach shouldn’t have worked, but it did,” said Andrew Brandt, principal threat researcher at Sophos.

The pre-patch versions of the attack involved malicious code packaged into a Microsoft Cabinet file. When Microsoft’s patch closed that loophole, attackers discovered a proof-of-concept that showed how you could bundle the malware into a different compressed file format, a RAR archive.

RAR archives have been used before to distribute malicious code, but the process used here was unusually complicated.

It likely succeeded only because the patch’s remit was very narrowly defined and because the WinRAR program that users need to open the RAR is very fault tolerant and doesn’t appear to mind if the archive is malformed, for example, because it’s been tampered with.”

The Infection Chain

Sophos researchers found that the attackers had created a rogue RAR archive that had a PowerShell script prepending a malicious Word document stored within the archive.

The attackers created and distributed spam emails that included the invalid RAR file as an attachment. The emails were inviting recipients to unzip the RAR file to access the Word document.

Opening the Word document triggered a process that, on unpatched systems, ran the front-end script, eventually leading to an infection with the Formbook malware.

This study is a reminder that patching alone cannot protect against all vulnerabilities in all cases.

Setting restrictions that prevent a user from accidentally activating a malicious document can help protect against such exploits, but people can still be tricked into clicking the “Enable Content” button.

It is therefore vital to educate employees and remind them to be wary of documents sent by email, especially when they arrive in unusual or unfamiliar compressed file formats from people or companies they do not know. If in doubt, always check with the sender or someone in IT

ByEditorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article Tech Ecosystem Australia State Of The Australian Tech Ecosystem
Next Article Fake Facebook Fake Facebook Accounts And Profiles Is An Ongoing Problem.
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Office Exploit

Tech Articles

Top Big Tech Companies 2026

The Big Tech Companies Actually Winning In 2026 — And Numbers That Prove It

Top tech companies in 2026 included AppLovin, AWS, Microsoft, Meta,…

May 20, 2026
The Decay of guest blogging posts

The Decay of Guest Blogging. It Got Cheap, Automated, and Spammy.

Guest blogging once helped publishers showcase real expertise and build…

June 9, 2026
Your Phone Is Spying on You and tracking location

Your Phone Is Spying on You — Here’s How to Stop It

Your phone is spying, tracking your location, searches, app activity,…

July 11, 2026

Recent News

AUCloud New Research Uncovers Cyber Threat to Aussie Businesses - Peter Maloney -Tech News
Cyber

New Research Uncovers Cyber Threat to Aussie Businesses

3 Min Read
Australian Companies Pay Ransomware Demands
Cyber

Most Australian Companies Would Pay Ransomware Demands

3 Min Read
Diligent Launches AI-Powered Cyber Risk Management to Put Business Impact at the Center of Security Decisions
Cyber

Boards Are Demanding Simpler Cyber Answers — Risk Management Companies Say They Can Deliver

4 Min Read
Palo Alto Networks CyberFit
CyberEducation

Palo Alto Networks Launches CyberFit Nation Education Program

6 Min Read
Tech News - Technology Business

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.
 
Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.
 
Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

July, 23, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?