Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on infosec.pub
research·Researchbyexecveat

Every Signature is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures

OOXML signatures are rendered pretty much useless due to 3 flaws in specification and 2 flaws in implementation.

"The vulnerabilities have been acknowledged by Microsoft. However, Microsoft has decided that the vulnerabilities do not require immediate attention."

https://www.usenix.org/system/files/sec23summer_235-rohlmann-prepub.pdfOpen linkView original on infosec.pub
2

No replies yet

No comments on the original post yet.
Every Signature is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures | Spyke