October 13, 2006

Microsoft warns of new PowerPoint attack

Warning comes just days after patching four bugs in Microsoft's presentation software

Just days after patching four bugs in PowerPoint, Microsoft is warning of a new attack targeting its presentation software.

"We’ve been made aware of proof of concept code published publicly affecting Microsoft Office 2003 PowerPoint," wrote Microsoft Security Program Manager Alexandra Huft in a Thursday blog posting. "The reported proof of concept may allow an attacker to execute code on a user’s machine by convincing them to open a specially-crafted PowerPoint file."

Huft said that Microsoft is not aware of any attacks that take advantage of the bug, but with code now in circulation on public Web sites like Securitydot.net, the attack is easily available to attackers.

Her blog entry can be found here.

Security vendor Secunia rates the flaw as highly critical because it could be exploited to gain accessed to a fully patched Windows system.

The flaw affects PowerPoint 2000, PowerPoint 2002 and PowerPoint 2003, as well as many versions of the Office suite, Secunia said. Its security advisory can be found here.

Hackers have been keeping Microsoft's security team extremely busy over the past month, and Office in particular has been the focus of their efforts. On Tuesday, Microsoft released the largest number of bug fixes in recent memory patching 26 flaws in its Windows, Office and .Net framework products.

Close

On Twitter now

Application development

Powered by Twitter

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive InfoWorld Resource Alerts

Subscribe to the Developer World Newsletter

Receive a weekly roundup about the art and science of software development.

©1994-2009 Infoworld, Inc.