Attackers exploited CVE-2023-36884, a Microsoft Office and Windows HTML remote code execution zero-day, in attacks involving RomCom malware. Microsoft disclosed the vulnerability, rated Important, during its July 2023 Patch Tuesday release, while Unit 42 confirmed exploitation dating to at least July 3. Observed attacks required victims to open specially crafted Office documents; the documented attack chain downloaded a script that initiated iframe injection and retrieved a malicious payload.
Microsoft subsequently released an Office security update that interrupts the attack chain, with related guidance published under ADV230003. Organizations should prioritize deploying the Office update. Where patching is not immediately possible, Microsoft recommended blocking Office applications from creating child processes or configuring the FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION setting to mitigate exposure.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Trellix published analysis showing how Storm-0978's Office documents embedded malicious RTF through AltChunk, triggering linked OLE retrieval and redirects leading to Windows .search-ms files and remote code execution. Researchers also demonstrated reconstruction of the document structure and published infection-chain indicators.
Microsoft reported that early exploitation of CVE-2023-36884 involved RomCom malware, which had previously appeared in ransomware and targeted espionage-related attacks.
Unit 42 confirmed exploitation dating to at least July 3, 2023. The observed attacks required users to open specially crafted Microsoft Office documents.
During its July 2023 Patch Tuesday release, Microsoft disclosed CVE-2023-36884, an Important-severity remote code execution vulnerability affecting Office and Windows HTML. Microsoft recommended blocking Office child processes or configuring FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION as interim mitigations.
Unit 42 first observed RomCom, a remote access Trojan later associated with early exploitation of CVE-2023-36884.
Unit 42's investigation uncovered a separate Mark-of-the-Web bypass that Microsoft designated CVE-2023-36584 and rewarded with a bug bounty. Researchers demonstrated three bypass techniques involving ZIP metadata inconsistencies or delayed SMB responses, but did not confirm attackers used the ZIP-swap technique.
Microsoft released an Office patch that stops the documented attack chain leading to exploitation of CVE-2023-36884. Unit 42 updated its brief on August 9, 2023, to include the released patch and recommended applying it.
Unit 42 documented how opening a malicious document downloads a script that initiates iframe injection and retrieves a malicious payload. Its threat brief listed file hashes, IP addresses and domains, and reported sharing findings, samples and indicators with Cyber Threat Alliance members.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 45 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourceunit42.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.