SB2017062710 - Backdoor in M.E.Doc software



SB2017062710 - Backdoor in M.E.Doc software

Published: June 27, 2017 Updated: July 2, 2017

Security Bulletin ID SB2017062710
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Backdoor (CVE-ID: N/A)

The security issue exists due to presence of backdoor code in updates, distributed from the official website. After update installation, the system becomes infected with NotPetya ransomware.

Malware, present in the code, also performs various attempts to infect other systems.

Remediation

Install update from vendor's website.