Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums

Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums

Posted on November 20, 2025November 20, 2025 By CWS

A risk actor generally known as Zeroplayer has reportedly listed a zero-day distant code execution (RCE) vulnerability, mixed with a sandbox escape, concentrating on Microsoft Workplace and Home windows programs on the market on underground hacking boards.

Priced at $30,000, the exploit purportedly works on most Workplace file codecs, together with the most recent variations, and impacts absolutely patched Home windows installations.

This growth raises alarms within the cybersecurity group, because it may allow attackers to bypass Microsoft’s sturdy sandbox protections and execute arbitrary code with minimal person interplay.

The commercial, posted in Russian on a outstanding hacking discussion board, describes the vulnerability as a high-impact 0-day able to delivering payloads by way of malicious Workplace paperwork.

Zeroplayer claims the exploit chain permits distant attackers to flee the Workplace sandbox a important safety characteristic designed to isolate doubtlessly dangerous code—and obtain full system compromise on Home windows.

Supply strategies contain embedding the exploit in widespread file sorts like Phrase or Excel paperwork, which might be distributed by way of phishing emails or compromised web sites.

Alleged Microsoft Workplace 0-Day Declare

Particulars of the Hacker Discussion board Itemizing

The vendor invitations non-public messages for demonstrations and proof-of-concept particulars, emphasizing compatibility with latest updates to mitigate detection by antivirus instruments.

This isn’t Zeroplayer’s first foray into the exploit market; the actor beforehand provided a WinRAR zero-day RCE for $80,000 in July 2025, highlighting a sample of concentrating on extensively used productiveness and archiving software program.

Such gross sales underscore the profitable underground economic system for zero-days, the place exploits fetch premium costs earlier than public disclosure or patching.​

Microsoft’s November 2025 Patch Tuesday addressed a number of important RCE flaws in Workplace, together with CVE-2025-62199, a use-after-free vulnerability exploitable by way of malicious paperwork.

Nevertheless, that patch centered on identified points and didn’t reference this alleged 0-day, suggesting it stays unpatched and doubtlessly extra harmful as a result of its sandbox escape part.

Sandbox escapes are notably regarding, as they neutralize one in all Workplace’s major defenses in opposition to macro-based assaults, permitting malware to unfold laterally throughout networks.​

Specialists notice that Russian-language boards just like the one internet hosting this itemizing usually function hubs for state-affiliated or opportunistic risk actors, who might weaponize such exploits for ransomware, espionage, or knowledge theft.

Comparable previous incidents, such because the 2023 exploitation of CVE-2023-36884 by the Russian group Storm-0978, concerned Workplace RCE for backdoor deployment in opposition to Western targets.​

The potential fallout from this 0-day is important, particularly for enterprises reliant on Microsoft 365. Attackers may leverage it to compromise provide chains or conduct focused intrusions, evading endpoint detection responses.

Given Workplace’s ubiquity throughout over 1.4 billion gadgets globally, unpatched programs face a heightened threat of an infection by way of spear-phishing.​

Organizations ought to prioritize macro disabling in Workplace insurance policies, allow Protected View for all paperwork, and deploy superior risk safety instruments.

Monitoring for anomalous discussion board exercise and making use of upcoming patches urgently is suggested, as Microsoft might speed up fixes if exploitation proof emerges.

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:0Day, Actors, Allegedly, Forums, Hacking, Microsoft, Office, RCE, Selling, Threat, Vulnerability

Post navigation

Previous Post: Vulnerability Allowed Scraping of 3.5 Billion WhatsApp Accounts
Next Post: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves

Related Posts

Threat Actors Using Stealerium Malware to Attack Educational Organizations Threat Actors Using Stealerium Malware to Attack Educational Organizations Cyber Security News
Microsoft Identifies Fake AI Extensions Breaching Enterprises Microsoft Identifies Fake AI Extensions Breaching Enterprises Cyber Security News
eFAQ Exposes Coordinated Online Reputation Attack eFAQ Exposes Coordinated Online Reputation Attack Cyber Security News
Konni APT Exploits KakaoTalk in Malware Campaign Konni APT Exploits KakaoTalk in Malware Campaign Cyber Security News
Cybercriminals Exploit Fake Avast Site for Credit Card Data Cybercriminals Exploit Fake Avast Site for Credit Card Data Cyber Security News
Network Security Checklist – 2026 Network Security Checklist – 2026 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark