You are here: silicon.com > Software > Malware

Malware

Hackers get cracking on unpatched PowerPoint flaw

Where's the patch?

Tags: powerpoint, microsoft, patch, flaw

By Tom Espiner

Published: 3 April 2009 15:51 GMT

Hackers have launched attacks targeting an unpatched flaw in Microsoft PowerPoint, Microsoft warned on Thursday.

The vulnerability, which affects Microsoft Office 2000 SP3, 2002 SP3 and 2003 SP3, can be exploited by getting a user to open a PowerPoint file rigged for the attack. When the file is opened, PowerPoint will access an invalid object in memory. That then allows an attacker to remotely execute code on the system.

In a security advisory, Microsoft said that at present, attacks are not widespread, but they are tailored to affect specific victims.

"Microsoft is investigating new reports of a vulnerability in Microsoft Office PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file," said the advisory. "At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability."

While there is currently no fix for the PowerPoint flaw, Microsoft said that it may release one outside its monthly patching schedule. Workarounds suggested by the company include users not opening files received from untrusted sources, using the Microsoft Office Isolated Conversion Environment (MOICE) to open untrusted files, and using Microsoft Office File Block policy to restrict the opening of Office 2003 and earlier documents.

Microsoft's last major PowerPoint patch, which came out in August 2008, addressed three critical flaws in the software.

Original article: Zero-day PowerPoint flaw gives rise to attacks from ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Localisation Engineer

Identifies and prepares files for localisation. Manages files using version control systems. Generates word counts for files to be translated. ...

Consultant

A good working knowledge of Microsoft Office products (mainly Word, Excel and Powerpoint) is a essential. s budgetary and resource requirements.c) ...

Information Security Analyst (Attack Monitoring/Data Leakage/CISSP/CEH

You must have previous experience in a dedicated vulnerability management function where you have been responsible for all potential attacks on a ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: