FortiGuard
Fortinet’s Global Threat Intelligence and Research
Pwalia
Staff
Staff
Article Id 265059

Description

Microsoft has identified a phishing campaign conducted by the threat actor tracked as Storm-0978 targeting defense and government entities in Europe and North America. The campaign involved the abuse of CVE-2023-36884, a remote code execution vulnerability exploited via specially crafted Microsoft Office documents spread using phishing techniques.

CVEs

CVE-2023-36884

Severity

High

Posted On

Jul 13, 2023

Outbreak Report Link

https://www.fortiguard.com/outbreak-alert/microsoft-office-and-windows-html-attack

Contributors