After patches, Microsoft warns of PowerPoint attack
Just days after patching four bugs in PowerPoint, Microsoft Corp. is warning of a new attack targeting its presentation software.
"We've been made aware of proof of concept code published publicly affecting Microsoft Office 2003 PowerPoint," wrote Microsoft Security Program Manager Alexandra Huft in a Thursday blog posting. "The reported proof of concept may allow an attacker to execute code on a user's machine by convincing them to open a specially-crafted PowerPoint file."
Huft said that Microsoft is not aware of any attacks that take advantage of the bug, but with code now in circulation on public Web sites like Securitydot.net, the attack is easily available to attackers.
Her blog entry can be found here: http://blogs.technet.com/msrc/archive/2006/10/12/poc-published-for-ms-office-2003-powerpoint.aspx
Security vendor Secunia rates the flaw as highly critical because it could be exploited to gain accessed to a fully patched Windows system.
The flaw affects PowerPoint 2000, PowerPoint 2002 and PowerPoint 2003, as well as many versions of the Office suite, Secunia said. Its security advisory can be found here: http://secunia.com/advisories/22394/
Hackers have been keeping Microsoft's security team extremely busy over the past month, and Office in particular has been the focus of their efforts. On Tuesday, Microsoft released the largest number of bug fixes in recent memory patching 26 flaws in its Windows, Office and .Net framework products.
IDG News Service
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
jfruh
Apple syncing patent can't come soon enough
pasmith
New Twitter features borrow from 3rd party clients
Esther Schindler
Open Source Changes the Software Acquisition Process
mikelgan
How to set up continuous podcast play on the new iTunes
David Strom
Five important Windows 7 mobility features
sjvn
Guard your Wi-Fi for your own sake
Sandra Henry-Stocker
Grepping on Whole Words
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.













