Kaspersky Lab says ~70% of the attacks its products detected in Q4 2018 targeted Office vulnerabilities, four times the percentage it saw in Q4 2016
Context & Ripple Effects
Kaspersky Lab's detection data shows attackers pivoting away from the operating system and toward the document layer: by Q4 2018, roughly 70% of what its products caught targeted Office vulnerabilities, a fourfold jump from two years earlier. The lab had already been watching this space closely — its researchers were the ones who noticed multiple cyber-espionage groups abusing a Windows zero-day escalation-of-privilege bug that Microsoft patched in November 2018.
The pattern foreshadowed what came next: when the SolarWinds fallout spread, Malwarebytes disclosed it was breached through Azure and Office 365 exploits, confirming cloud-hosted productivity suites as a first-class target rather than just an on-premises one.
First-order effects
- Enterprises running Office face a concentrated patching burden: with ~70% of detected attacks aimed at Office flaws, unpatched document-handling components become the single most exposed part of the Windows estate.
- Microsoft's security response priorities shift, since the exploit surface its own telemetry now flags most is Office rather than the OS kernel.
Second-order effects
- Endpoint vendors compete on detecting malicious documents and macros rather than binary malware, pushing product roadmaps toward content inspection at the mail and file layer.
- Attack economics favor Office-based entry because a single document flaw reaches nearly every corporate desktop, reducing reliance on rarer OS-level bugs like the one Kaspersky flagged in late 2018.
Third-order effects
- If the trajectory holds, the productivity suite — not the operating system — becomes the de facto enterprise perimeter, and security budgets migrate from traditional endpoint protection toward email, document, and identity-layer defenses.
- The same logic extends to the cloud: once Office workloads moved to Azure and Office 365, suite-level exploits became a path into tenant data, as the Malwarebytes incident showed.
The trend: Enterprise attacks are migrating from operating-system vulnerabilities to productivity and document software, a shift that later carried over into cloud-hosted Office 365 environments.