Exploit Exposes PowerPoint Zero-Day Vulnerability


By Gregg Keizer, ChannelWeb

12:54 PM EDT Fri. Oct. 13, 2006
Just days after Microsoft issued a record 26 patches, including 16 for Office, on Friday Symantec confirmed that just-released exploit code attacks a new, zero-day vulnerability in the PowerPoint presentation software.

The exploit, which was posted to "milw0rm," a site that hosts an exploit database, successfully attacks PowerPoint 2003, even when the application has been fully patched, including the 4 fixes released Tuesday.

According to Symantec's alert, the exploit triggers a crash of PowerPoint. "It does not appear that the vulnerability can be leveraged to execute code, however the possibility has not been conclusively eliminated," said Symantec to customers of its DeepSight threat system. "[We have] tested the exploit and it is confirmed to work as advertised." Danish vulnerability tracker Secunia rated the threat as "highly critical," its second-highest warning rank.

The exploit can be delivered as a malformed PowerPoint file, Microsoft acknowledged. Microsoft's security team said Thursday that it was aware of the publicly-posted code and was investigating.

"We are not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time," wrote Alexandra Huft, a security program manager with the Microsoft Security Response Center, on the group's blog. "As part of our investigation, we are working with our MSRA [Microsoft Security Response Alliance] partners to monitor and secure the ecosystem."

Microsoft Office's applications have been patched repeatedly in 2006, with 44 vulnerabilities fixed in the suite so far this year. Eight of the 44, have specifically involved PowerPoint.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
30% off Virtualization Manager 2010 Corporate
Save 30% on Paragon Software Virtualization Manager 2010 Corporate. Our response to the typical problems of every modern comp...
Disaster Recovery for Servers
The next trend of backups for businesses are being used along with virtualization technology. With servers being consolidated...
RELATED BLOG >>
Photo
Everything Channel, in conjunction with the XChange advisory boards and key vendor executives, has been working to refresh the event's content and develop a track for solution-provider executives who want to transform business practices.
Media Kits | Reprints | Privacy Statement | Copyright © 2010 United Business Media LLC | Terms of Service
CRN Logo ChannelWeb Logo CRN Logo CRNTech Logo Everything Channel Events IPED
ADVERTISEMENT




CHANNEL SERVICES >>