Follina – Microsoft Zero-Day Vulnerability Proactive Reporting

Case Study

Scope of Work

Protection for clients from cyber-crime with the proactive reporting of our Network Services Support Program (NSSP)

Exploitation of Microsoft Office vulnerability: Follina

 

In August 2022 Microsoft tracked a new vulnerability, called Follina. It leveraged Microsoft Office to lure victims and execute code without their consent.

To put it simply, it was a vulnerability in Windows that was being used by State-backed hackers! When users opened a malware-infected document (even just a preview) it bypassed all warnings and infected individuals or network systems.

These security issues happen behind the scenes all the time as predatory countries constantly build ways to infiltrate systems to exploit companies and governments.

Even though there is cyber security legislation and dedicated departments in private and government teams who work continually to block these attacks, if you have a diligent monitoring system there is no need for alarm.

The Process

How do they plug up the hole in the system?

When your company is alerted that there is an update to install, part of that update will be one or more repairs (called patches) to the system. The system managers will have created a patch to protect your system from a detected breach.

In this case, Microsoft released a security patch called Patch Tuesday that dealt with Follina.

The Outcome

No HALL COMPUTER SERVICES clients were affected by the Microsoft Follina security hack as we applied the “fix” to all our clients immediately. Our NSSP system detected the problem early and we applied a patch that mitigated any attack on our clients’ systems as a standard procedure.

The Difference With Us

Our NSSP magical, 24/7/365 security system detected it in real-time, and we took immediate action.

We beat the Microsoft System operators by two weeks to repair and protect our clients who were not aware of the problem as it all happened seamlessly and was reported to them later.

HALL COMPUTER SERVICES were two weeks ahead of Microsoft!

What is Microsoft Follina Zero Day?

https://www.cyber.gov.au/acsc/view-all-content/alerts/exploitation-microsoft-office-vulnerability-follina