Skip to main content

Microsoft Reports Vulnerabilities Impacting Windows and Office Products

Microsoft Vulnerabilities

Published on

July 14, 2023

Bryan Siemon

Bryan Siemon

Microsoft Reports Vulnerabilities Impacting Windows and Office Products

Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products.

Microsoft reads, “An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.

Microsoft has confirmed no less than 132 security vulnerabilities across product lines, including six that fall into the “zero-day” category.

Microsoft suggested these applications would be impacted and is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially crafted Microsoft Office documents.

Office Products include:

– Excel – Publisher – PowerPoint – Word – WordPad – Access – Graph – Visio

An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.

SoHo Network Solutions has always encouraged its customers not to open email attachments they do not recognize or expect. Free antivirus solutions are better than nothing, however, they lack centralized management and advanced features that we can provide. Hackers have become more advanced, so more advanced solutions are needed. The good news is that paid professional-grade antivirus software has become more affordable than ever. For $4 a month per computer, you can get the protection needed to help combat these vulnerabilities.

The Technical Details:

The vulnerability is a remote code execution (RCE) vulnerability affecting Windows and Office product, CVE-2023-36884, with a CVSS score of 8.3. The targeted attacks exploit these vulnerabilities using specially crafted Microsoft Office documents.” CVE-2023-36884 is as yet unpatched.

If you have any questions or concerns about this, please don’t hesitate to call Soho Network Solutions at 717.831.8128. It is recommended you ensure you have all Windows and Office updates and a strong antivirus program.

About SoHo’s Antivirus Solution:

To purchase Professional-Grade Antivirus Software give us a call- 717.831.8128. SOHO Network Solutions offers the Malwarebytes EDR Cloud Managed solution for $4/workstation/month or $48/year.

How does EDR work?

Endpoint detection and response are broadly defined by three types of behavior.

Endpoint management

This refers to EDR’s ability to be deployed on an endpoint, record endpoint data, then store that data in a separate location for analysis now or in the future. EDR can be deployed as a standalone program or included as part of a comprehensive endpoint security solution. The latter has the added benefit of combining multiple capabilities into a single endpoint agent and offering a single pane of glass through which admins can manage the endpoint.

Data analysis

EDR technology can interpret raw telemetry from endpoints and produce endpoint metadata (or cyber threat intelligence) human users can use to determine how a previous attack went down, how future attacks might go down, and actions that can be taken to prevent those attacks.

Threat hunting

EDR scans for programs, processes, and files matching known parameters for malware. Threat hunting also includes the ability to search all open network connections for potential unauthorized access.

Incident response

Incident response refers to EDR’s ability to capture images of an endpoint at various times and re-image or rollback to a previous good state in the event of an attack. EDR also gives administrators the option to isolate endpoints and prevent further spread across the network. Remediation and rollback can be automated, manual, or a combination of the two.

Think of EDR as a flight data recorder for your endpoints. During a flight, the so-called “black box” records dozens of data points; e.g., altitude, air speed, and fuel consumption. In the aftermath of a plane crash, investigators use the data from the black box to determine what factors may have contributed to the plane crash … Likewise, endpoint telemetry taken during and after a cyberattack (e.g. processes running, programs installed, and network connections) can be used to prevent similar attacks.

More Articles


We Are A Full Service IT Company

We can help setup MFA in your organization. Contact us today to learn more or help getting started.

Continue reading

What is a Managed Service Provider

MSP

Published on

Bryan Siemon

Bryan Siemon

What is a Managed Service Provider (MSP)? A managed service provider (MSP) is a company that provides a range of IT services to a business on a contract basis. These services may include everything from setting up and maintaining computer systems to providing technical support and managing cybersecurity.

Businesses today operate in a complex and constantly evolving technological landscape. As businesses continue to rely heavily on technology to operate and grow, having a Managed Service Provider (MSP) is becoming increasingly important.

An MSP allows a business to focus on its core competencies and leave its technology management to experts.

Having an MSP on board can provide several benefits for businesses. An MSP allows a business to focus on its core competencies and leave its technology management to experts. With a hired MSP like SoHo Network Solutions, we are a company that provides a range of IT services, including monitoring, maintenance, and support for a business’s IT infrastructure. This allows your businesses to access the latest technology and our expertise without hiring, training, and managing an in-house IT team.

There are several reasons why a business should hire SoHo Network Solutions as its MSP:

  1. Cost savings: By outsourcing IT services to an MSP, a business can save money on the costs associated with hiring and training in-house IT staff. MSPs also typically have economies of scale, which allows them to provide services at a lower cost than what a business could do on its own.
  2. Expertise: MSPs specialize in providing IT services, so they have a high level of expertise in this area. This can be especially beneficial for businesses that don’t have the resources or knowledge to effectively manage their own IT systems.
  3. Proactive maintenance: MSPs often provide proactive maintenance services, which means they can identify and fix potential issues before they become major problems. This can help reduce downtime and keep a business running smoothly.
  4. Scalability: MSPs can help businesses scale their IT infrastructure as needed, whether that means adding new systems or upgrading existing ones. This can be especially useful for businesses that are growing rapidly and need to be able to adapt to changing needs.
  5. Security: Cybersecurity is a major concern for businesses, and MSPs can help protect against threats by providing a range of security services such as firewall management, virus protection, and data backup and recovery.

Additionally, an MSP can provide expert guidance and support to a business when it comes to making important IT decisions. This can include everything from selecting and implementing new technology solutions to planning for future IT needs and requirements.

Many businesses and organizations that do not have a full-time Network Administrator or IT person usually run on a “break-n-fix” model.

Many businesses and organizations that do not have a full-time Network Administrator or IT person usually run on a “break-n-fix” model. With “break-n-fix,” it can actually be more costly as you are not just paying for the technician’s hourly rate but any downtime it may create and employee inefficiencies. Hiring an MSP can help save you from this model and get your computer and data centers managed and monitored.

Furthermore, we emphasize data backup and disaster recovery services to ensure that a business can continue to operate even in the event of a major disruption or disaster. This includes full-image backup and recovery solutions, to help ensure business continuity planning and support.

In today’s technology-driven world, having an MSP is essential for businesses of all sizes. Not only can an MSP help save time and money, but it can also provide expert guidance and support, improved security, and disaster recovery services. By partnering with an MSP, a business can focus on its core competencies and goals, knowing that its IT infrastructure and systems are in good hands. SoHo Network Solutions provides the services that your business needs to stay competitive and succeed in an increasingly complex technological landscape.

More Articles


We Are A Full Service IT Company

We offer MSP services which include 24/7 system monitoring, patch management and remote support. Contact us today to learn more or help getting started.

Continue reading

Free vs Paid Antivirus

Professional Grade
Antivirus

Published on

Bryan Siemon

Bryan Siemon

Making the right choice

Anti-virus software is an essential tool for protecting your computer and personal information from malicious threats such as viruses, malware, and ransomware. While there are many free anti-virus programs available, paid software offers a number of additional benefits that make it worth the investment.

One of the biggest advantages of paid anti-virus software is the level of protection it provides. Paid software is typically more comprehensive than free versions, with a wider range of features and more frequent updates. This means that paid software is able to detect and block a wider range of threats, providing a higher level of security for your computer. This can include advanced features such as real-time protection, automatic updates, and the ability to scan for potential threats on external devices such as USB drives.

With free software, you may be limited in the amount of help you can receive if you encounter a problem or have a question.

Another benefit of paid anti-virus software is the level of support it offers. With free software, you may be limited in the amount of help you can receive if you encounter a problem or have a question. Paid software, on the other hand, typically comes with access to customer support and technical assistance, so you can get the help you need if you run into any issues.

Paid anti-virus software also often includes additional features and tools that can help to protect your computer and your personal information. For example, many paid programs include features like firewall protection, parental controls, and password managers, which can help to keep your computer and your personal data safe.

Investing in paid antivirus software can save you money in the long run. While a free version may seem like a good deal initially, the lack of comprehensive protection and support can end up costing you more in the form of lost or stolen data and potential repair costs.

In addition to providing more comprehensive protection and support, paid anti-virus software can also be more convenient to use. Paid software often includes automatic updates and scheduling options, so you can set it to run scans and updates at regular intervals without having to remember to do so manually. This can save you time and hassle and ensure that your computer stays protected even when you’re busy.

Free vs Paid

Free vs Paid? It is simple. Anti-virus software is an essential tool for protecting your computer and personal information from malicious threats such as viruses, malware, and ransomware. Paid software gives you comprehensive protection, additional security features, and better customer support. This can help protect your personal information and prevent potential issues from arising.

Overall, while free anti-virus software can provide some level of protection for your computer, paid software offers several additional benefits that make it worth the investment. Paid anti-virus software is an essential tool for keeping your computer and your personal information safe from online threats.

Paid software gives you comprehensive protection, additional security features, and better customer support.

SoHo Network Solutions offers the best in anti-virus protection for both home and business use. The importance of protection for your computers, servers and sensitive information are becoming more necessary in this digital world full of hackers and scammers. With over fifteen years of experience with Antivirus programs, we make sure we have only the best for our customers. Click on the button below to purchase Antivirus software today.

Purchase

More Articles


We Are A Full Service IT Company

We can help setup MFA in your organization. Contact us today to learn more or help getting started.

Continue reading