Another PowerPoint bug threatens users

By Joris Evers, CNET News.com
Tuesday, October 17, 2006 12:20 PM

Microsoft is investigating a report of a new, yet-to-be-fixed security vulnerability in PowerPoint, the company said late last week.

Sample attack code that exploits the vulnerability has already been released on the Internet, a Microsoft representative wrote on a corporate blog. Use of the code in an attack could cause a complete system compromise, according to Microsoft.

"The reported proof of concept may allow an attacker to execute code on a user's machine by convincing them to open a specially-crafted PowerPoint file," wrote Alexandra Huft, a Microsoft Security Response representative. "We are not aware of any attacks attempting to use the reported vulnerability."

The flaw affects PowerPoint 2003, according to Microsoft. Security monitoring companies Secunia and the French Security Incident Response Team, or FrSIRT, also list earlier versions as vulnerable. Secunia deems the issue "highly critical", while FrSIRT rates it "critical".

"The vulnerability is caused (by) an unspecified error when processing PowerPoint presentations," Secunia wrote in an advisory. For protection, people should not open Office documents received from untrusted sources, FrSIRT advices.

Word of the new PowerPoint flaw came only days after Microsoft last week released a slew of patches for Windows and Office. Several of the Office fixes were for flaws that also had previously been disclosed and some had been used in targeted cyberattacks.

Miscreants are taunting Microsoft with zero-day code, or attack code released immediately after a flaw or patch is made public, experts have said. Some security watchers have started to coin the term "zero-day Wednesday" to come after "Patch Tuesday", Microsoft's patch day on the second Tuesday of each month.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web