The exploit enables an attacker to download a “template” for Microsoft Office that is actually an encoded PowerShell command. When this is analysed by the MSDT it is decoded and the code is executed on the target system.
Due to the nature of the vulnerability, the malicious files do not even need to be opened to execute the code.
This vulnerability poses a serious risk to organisations running Microsoft Office. However, while there is no official patch for the issue, temporary mitigations can be implemented.
Disabling the ms-msdt scheme handler would prevent the vulnerability and can be done by executing the following code:
<p>reg delete hkcr\ms-msdt /f</p>
Disabling the Microsoft Troubleshooter using the following command can also mitigate the vulnerability:
<pre style="line-height: 18.0pt; background: #2F2F2F; margin: 6.0pt 0cm 6.0pt 0cm;"><code><span style="font-size: 12.0pt; color: #eeeeee; background: #2F2F2F;">reg add </span></code></pre> <pre style="line-height: 18.0pt; background: #2F2F2F; margin: 6.0pt 0cm 6.0pt 0cm;"><code><span style="font-size: 12.0pt; color: #eeeeee; background: #2F2F2F;">HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnostics /f </span></code></pre> <pre style="line-height: 18.0pt; background: #2F2F2F; margin: 6.0pt 0cm 6.0pt 0cm;"><code><span style="font-size: 12.0pt; color: #eeeeee; background: #2F2F2F;">/v EnableDiagnostics /d 0 </span></code><span style="font-size: 12.0pt; color: #eeeeee;"></span></pre>
Should you have any queries about this alert, please feel free to contact us via the Ask The Expert section of our Response App, or by emailing our team at CyberThreatAnalysis@cfc.com