Critical security flaws found in Office Open XML signatures

Share post:

Researchers at Germany’s Ruhr University Bochum uncovered security flaws in Office Open XML (OOXML) signatures used in Microsoft Office and OnlyOffice. These weaknesses make it simple to spoof and fabricate Office files with false signatures.

The findings were presented in a paper titled “Every Signature is Broken” scheduled to be presented at the USENIX Security Symposium. These flaws were discovered in various versions of Microsoft Office for Windows and macOS, as well as in OnlyOffice Desktop for Windows, macOS, and Linux. Microsoft Office for macOS does not check document signatures, allowing an empty file to be added to an OOXML package and a fake security flag to be shown.

Simon Rohlmann, the lead author, criticized the use of partial signatures in OOXML, compromising information integrity and authenticity. He noted that other formats like ODF have resolved this issue effectively. He added that OOXML documents are vulnerable to manipulation. This is because they use partial signatures, which allow attackers to create forged signatures that appear to be from a trusted source. The vulnerabilities stem from three main issues: partial signatures, flaws in the rendering flow, and a complex cryptographic verification process.

Microsoft acknowledged the vulnerabilities, offered a bug bounty, but didn’t see an immediate need for action. OnlyOffice hasn’t responded since October 2022.

The sources for this piece include an article in TheRegister.

SUBSCRIBE NOW

Related articles

Employee errors still predominant cause of data breaches: Verizon Report

In the latest 2024 Verizon Data Breach Report (DBIR), it has been revealed that employee errors remain the...

Black Basta has compromised over 500 organizations globally:CISA

The Cybersecurity and Infrastructure Security Agency (CISA) along with the FBI reported that the Black Basta ransomware group...

Cyber Security Today, May 10, 2024 – Patches for F5’s Next Central Manager released, Dell discovers data theft covering millions, and more

Patches for F5's Next Central Manager are released, Dell discovers data theft covering millions of buyers, and more Welcome...

Cyber Security Today, May 8, 2024 – The alleged LockBit ransomware leader is identified, and the gang makes false claims of new victims

The alleged LockBit ransomware leader is identified, and the gang makes false claims of new victims. Welcome to Cyber...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways