Automatically translated.View original post

Microsoft Release Emergency Update on Office 2016-2024 🚨

Microsoft has issued an Out-of-band Emergency Security Update to fix the Zero-Day vulnerability on Microsoft Office that is currently being exploited. The vulnerability contains the code CVE-2026-21509 and is classified as high intensity 7.8/10 points.

.

This vulnerability is a Security Feature Bypass type caused by the Office trusting some data that should not be trusted, allowing an attacker to evade OLE protection mechanisms designed to protect against the danger of vulnerable COM / OLE Controls.

.

This vulnerability can only be attacked if the user accidentally opens an Office file sent by a hacker, such as a Word or Excel file, that has a malicious code embedded. The attacker must first deceive the victim to open the file to attack or embed the malware.

.

This vulnerability affects several versions of Microsoft Office, including Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft 365 Apps for Enterprise.

.

Microsoft reiterated that users will not be attacked by simply clicking Preview File in the Explorer window because Preview Pane is not a channel where this vulnerability can be exploited.

.

For Office 2021 and above users, including Microsoft 365, patches have now come out to plug the vulnerability with automatic updates, but Office 2016 and Office 2019 have no immediate patches, with Microsoft stating that updates will be released as soon as possible.

.

In the meantime, administrators can mitigate the risk by adjusting the Windows Registry to disable the COM Object associated with the vulnerability, although that method may affect some program operations and should only be used as a temporary measure.

.

Microsoft recommends that users avoid opening Office files from untrusted sources, and should install security updates immediately when they are available, to protect against potential attack risks.

.

Source: bleepingcomputer

# IT News # Includes IT matters # Cough to know # IT

2/3 Edited to

... Read moreถ้าใครกำลังค้นหา “รูปถ่ายของ Microsoft” แล้วเจอภาพกล่อง Microsoft Office หลายเวอร์ชัน (2016, 2019, 2021, 2024) พร้อมไอคอน Word/Excel/PowerPoint แบบในโพสต์นี้ เราว่ามันเป็นรูปที่เตือนสติได้ดีมาก เพราะรอบนี้ไม่ใช่แค่ข่าวอัปเดตทั่วไป แต่เป็นอัปเดตฉุกเฉินเพื่ออุดช่องโหว่ Zero‑day ที่มีความอันตรายระดับ 7.8/10 และมีรายงานว่าถูกใช้โจมตีจริงแล้ว จากที่อ่านรายละเอียดมา ประเด็นสำคัญคือ “โดนโจมตีได้เมื่อเราเผลอเปิดไฟล์ Office ที่ถูกส่งมา” เช่นไฟล์ Word หรือ Excel ที่ฝังโค้ดอันตรายไว้ ดังนั้นสิ่งที่ช่วยได้มากที่สุดในชีวิตจริงคือการลดโอกาส “เปิดไฟล์ผิด” มากกว่าตื่นตระหนกกับการแค่เห็นไฟล์ในเครื่อง สิ่งที่เราใช้เช็กเองแบบง่าย ๆ (เหมาะกับคนทั่วไป) 1) เช็กเวอร์ชัน Office ที่ใช้อยู่: หลายคนมี Office หลายรุ่นในบ้าน/ที่ทำงาน บางเครื่องเป็น Office 2016/2019 ที่อาจยังไม่ได้แพตช์ทันที ควรเข้าไปที่ Account > About (หรือเมนูบัญชี) เพื่อดูเวอร์ชันและช่องทางอัปเดต 2) อัปเดตทันทีเมื่อมีแพตช์: ถ้าใช้ Microsoft 365 หรือ Office 2021 ขึ้นไป ปกติระบบจะอัปเดตอัตโนมัติ แต่เราแนะนำให้กด “Update Now” เพื่อเร่งตรวจสอบอีกครั้ง 3) ระวังไฟล์แนบและลิงก์ดาวน์โหลด: อีเมล/แชตที่เร่งให้เปิดไฟล์, แจ้งหนี้/ใบเสนอราคา, หรือไฟล์ที่ชื่อคล้ายเอกสารด่วน ๆ ให้สงสัยไว้ก่อน โดยเฉพาะไฟล์ที่มาจากคนนอกองค์กรหรือแหล่งที่ไม่รู้จัก คำถามที่หลายคนกังวล: แค่คลิกดูพรีวิวใน Explorer จะติดไหม? Microsoft ระบุชัดว่าการดูตัวอย่างไฟล์ใน Preview Pane ไม่ใช่ช่องทางโจมตีของช่องโหว่นี้ นี่ช่วยให้สบายใจขึ้นระดับหนึ่ง แต่ก็ยังไม่ควร “เปิดไฟล์จริง” ถ้าไม่มั่นใจแหล่งที่มา ถ้าเป็นฝ่าย IT/ดูแลหลายเครื่อง ในช่วงที่บางเวอร์ชันยังรอแพตช์ (เช่น Office 2016/2019) อาจต้องใช้มาตรการชั่วคราว เช่นการตั้งค่าใน Windows Registry เพื่อปิดการทำงานของ COM Object ที่เกี่ยวข้อง (ย้ำว่าอาจกระทบการใช้งานบางอย่าง) ควรทดสอบกับเครื่องกลุ่มเล็กก่อน แล้วค่อยขยายผล สรุปสั้น ๆ: รูปถ่าย Microsoft Office ในโพสต์นี้ไม่ได้มีไว้สวยอย่างเดียว แต่เป็น “ป้ายเตือน” ให้เราอัปเดตด่วน และระวังการเปิดไฟล์ Office จากแหล่งที่ไม่น่าเชื่อถือ โดยเฉพาะช่วงที่ Zero‑day กำลังถูกใช้โจมตีจริง