Security Problems Of Using The Microsoft Office Package

Dmitry Kuts, Sergey V. Porshnev, Maria Kuts, Д. Э. Терехин, Sergey Dolbikov, Sokolov Ilya · 2024

For many years, the Microsoft Office package has actually been a standard tool for processing electronic documents. Its vast capabilities and rich functionality set it apart from existing competitors. However, from the point of view of information security, extensive features and functionality are not always a boon. MS Office documents, primarily MS Word text editor documents, are often used by attackers as the main, as well as an intermediate stage in many types of attacks on computer systems. Built-in support for powerful and functional programming languages in office packages creates additional opportunities for the violator. In this article, we have reviewed several well-known vulnerabilities, for the successful exploitation of which it is necessary to use MS Word at one of the stages of the attack. The paper analyzes the potential threats created by the use of MS Office and other popular office packages in organizations. The features and functionality of office packages are described, in terms of using them for malicious purposes. To neutralize such threats recommendations on the safe configuration of office packages in the organization are made.

Read the paper · More papers on PaperTik