Nasty 0 Day doing the rounds at the moment
Recommended route to fix this is the Attack Surface Reduction Rule Block all Office applications from creating child processes
Deploying this through Intune is Simple , but what about servers? Remember Intune only works with Windows Devices
ASR rules actually work for Servers IF they have been onboarded into Defender
Make sure the ASR policy Targets MicrosoftSense
Onboarded in MDE is MicrosoftSense
MDM is Intune
Items that work on MDR in ASR Attack surface reduction rules reference | Microsoft Learn