Jump to content

Microsoft warns of Windows 0-day hack via PowerPoint


Recommended Posts

http://cdn.mos.techradar.com/art/TRBC/Videoconferencing/Polycom/CX5500/CX5500%20camera%20application%20image-470-75.jpg

Using Windows? Then be wary of PowerPoint files sent to you as they might be a doorway for hackers to take control of your computer.

Microsoft has issued a security advisory regarding a vulnerability in in its OLE (Object Linking and Embedding) feature that could allow a third-party to execute code remotely.

OLE has been a very useful feature available in Microsoft Office applications for nearly a quarter of a century now and allows you to bring a file within another (e.g. a video in a document).

While OLE-linked advisories have been issued in the past, what makes this one worthy of notice is the fact that it is unpatched and affects all versions of Windows bar Server 2003.

Not everyone however is convinced of its importance. Tripwire's Lamar Bailey reckons that it is not a major issue.

He added "The vulnerability is just an escalation of privilege issue and requires a watering hole attack and/or persuading the victim to open a file to exploit."

In other word, the target needs to do most of the leg work – and be gullible enough - in order for the trick to work.

If you don't open PowerPoint files from unknown sources and have UAC (User Account Control), then it's likely that you're not a risk.

http://rss.feedsportal.com/c/669/f/415085/s/3fc1585a/sc/4/mf.gif


http://da.feedsportal.com/r/211596779976/u/49/f/415085/c/669/s/3fc1585a/sc/4/rc/1/rc.img
http://da.feedsportal.com/r/211596779976/u/49/f/415085/c/669/s/3fc1585a/sc/4/rc/2/rc.img
http://da.feedsportal.com/r/211596779976/u/49/f/415085/c/669/s/3fc1585a/sc/4/rc/3/rc.img

http://da.feedsportal.com/r/211596779976/u/49/f/415085/c/669/s/3fc1585a/sc/4/a2.imghttp://pi.feedsportal.com/r/211596779976/u/49/f/415085/c/669/s/3fc1585a/sc/4/a2t.imghttp://feeds.feedburner.com/~r/techradar/software-news/~4/RNKIiLRlxhs
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...