LevelBlue + SentinelOne Partner to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

Microsoft Word RTF 0-Day (CVE-2014-1761)

A zero-day vulnerability in Microsoft Word involving the handling of the RTF file format was published last week in the form of a Microsoft advisory. In its advisory, Microsoft states that it is aware of "limited, targeted attacks" exploiting this vulnerability.

With more technical details regarding the vulnerability itself becoming available, we can confirm and reassure our customers that this attack is blocked by Trustwave's Secure Web Gateway. No updates are required for this to happen, the attack will be blocked by the following policy rule: "Block Malformed Binary Format Vulnerabilities (Binary VAD Engine)", so please be sure to have this rule enabled in your policy.

For the non-corporate users who wish to remain protected until an update is released, Microsoft has released a Fix-It tool to help mitigate the problem.

ABOUT LEVELBLUE

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

https://www.levelblue.com/resources/blogs/internal-blog/how-to-create-a-blog-post/

Latest Intelligence

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo