This malicious Word doc doesn’t even have to be opened to infect your PC

Last week, cybersecurity researcher Joshua Drake published a proof-of-concept for a vulnerability in Microsoft Word describing a way for threat actors to deliver malware (opens in new tab) without users ever having to open a file.

The vulnerability is tracked as CVE-2023-21716. It has been given a severity score of 9.8 and is considered critical because it allows remote code execution.