Empire Macro Fun
- by Vince
-
in Blog
-
Hits: 2640
There are a number of methods which use macros in Office documents to deploy malware. I came across one the other day that leverages a vulnerability in various versions of the .NET Framework.
CVE 2017-8759 -- Microsoft .NET Framework versions allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
There are three pieces to this exploit -- the Word document, a text file which will get downloaded when the macros are enabled, and .hta file with a payload. With a patched machine and current antivirus, I attempted to get this working but I could never get proper execution for whatever reason.