{"id":21038,"date":"2026-02-12T03:53:27","date_gmt":"2026-02-12T03:53:27","guid":{"rendered":"https:\/\/microvibenews.com\/?p=21038"},"modified":"2026-02-12T03:53:27","modified_gmt":"2026-02-12T03:53:27","slug":"microsoft-says-hackers-are-exploiting-critical-zero-day-bugs-to-target-windows-and-office-users","status":"publish","type":"post","link":"https:\/\/microvibenews.com\/?p=21038","title":{"rendered":"Microsoft says hackers are exploiting critical zero-day bugs to target Windows and Office users"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Microsoft has rolled out fixes for security vulnerabilities in Windows and Office, which the company says are being actively abused by hackers to break into people\u2019s computers.<\/p>\n<p class=\"wp-block-paragraph\">The exploits are <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#zero-click-one-click-attacks\" target=\"_blank\" rel=\"noreferrer noopener\">one-click attacks<\/a>, meaning that a hacker can plant malware or gain access to a victim\u2019s computer with minimal user interaction. At least two flaws can be exploited by tricking someone into clicking a malicious link on their Windows computer. Another can result in a compromise on opening a malicious Office file.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerabilities are known as <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#zero-day\" target=\"_blank\" rel=\"noreferrer noopener\">zero-days<\/a>, because the hackers were exploiting the bugs before Microsoft had time to fix them.<\/p>\n<p class=\"wp-block-paragraph\">Details of how to exploit the bugs have been published, Microsoft said, potentially increasing the chance of hacks. Microsoft did not say where they had been published, and a Microsoft spokesperson did not immediately comment when reached by TechCrunch.\u00a0In its bug reports, Microsoft acknowledged the input of security researchers in Google\u2019s Threat Intelligence Group in their discovery of the vulnerabilities.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Microsoft said one of the bugs, officially tracked as <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-21510\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-21510<\/a>, was found in the Windows shell, which powers the operating system\u2019s user interface. The bug affects all supported versions of Windows, the company said. When a victim clicks on a malicious link from their computer, the bug allows hackers to bypass Microsoft\u2019s SmartScreen feature that would typically screen malicious links and files for malware.<\/p>\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2026\/2\/10\/the-february-2026-security-update-review\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security expert Dustin Childs<\/a>, this bug can be abused to <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#remote-code-execution\" target=\"_blank\" rel=\"noreferrer noopener\">remotely plant malware<\/a> on the victim\u2019s computer.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThere is user interaction here, as the client needs to click a link or a shortcut file,\u201d Childs wrote in his blog post. \u201cStill, a one-click bug to gain code execution is a rarity.\u201d<\/p>\n<p class=\"wp-block-paragraph\">A Google spokesperson confirmed that the Windows shell bug was under \u201cwidespread, active exploitation,\u201d and said successful hacks allowed the silent execution of malware with high privileges, \u201cposing a high risk of subsequent system compromise, deployment of ransomware, or intelligence collection.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Another Windows bug, tracked as <a rel=\"nofollow\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-21513\">CVE-2026-21513<\/a>, was found in Microsoft\u2019s proprietary browser engine, MSHTML, which powers its legacy and long-discontinued Internet Explorer browser. It\u2019s still found in newer versions of Windows to ensure backward compatibility with older apps.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Microsoft said this bug allows hackers to bypass security features in Windows to plant malware.<\/p>\n<p class=\"wp-block-paragraph\">According to independent security reporter Brian Krebs, Microsoft also patched <a rel=\"nofollow\" href=\"https:\/\/krebsonsecurity.com\/2026\/02\/patch-tuesday-february-2026-edition\/\">three other zero-day bugs<\/a> in its software that were being actively exploited by hackers.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/02\/11\/microsoft-says-hackers-are-exploiting-critical-zero-day-bugs-to-target-windows-and-office-users\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has rolled out fixes&hellip; <\/p>\n","protected":false},"author":1,"featured_media":21039,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[249],"tags":[1662,12748,2235,12749,5015,12750],"_links":{"self":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/21038"}],"collection":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=21038"}],"version-history":[{"count":0,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/21038\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/media\/21039"}],"wp:attachment":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=21038"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=21038"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=21038"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}