This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Another Day, Another 0-day - PPT vuln

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1740
Last Updated: 2006-09-28 02:09:35 UTC
"Microsoft confirms yet another powerpoint vulnerability that leads to code execution… McAfee has a writeup* of the exploit they detected against this vulnerability to connect back to… mylostlove1 .6600 .org/[CENSORED] but variants of this will most likely connect to other places… It seems all supported versions of Office are affected. It's interesting to note that Microsoft also lists the Apple versions of Office as vulnerable. Delivery vectors are basically all means to get the file to you, including web, email, thumb drives, CDs…"
> http://www.microsoft.com/technet/security/…ory/925984.mspx

* http://www.avertlabs.com/research/blog/?p=95

:ph34r:
FYI…

- http://blog.washingtonpost.com/securityfix…attacks_on.html
October 2, 2006
"…What's probably most interesting about this PowerPoint flaw, according to a blog post from anti-virus maker McAfee*, is the fact that it appears that Microsoft's antivirus product added detection for this exploit back on Sept. 23, but the company didn't put out a public advisory on the threat until Sept. 27. McAfee said the delay suggests that "Microsoft's security team knew of this in-the-wild attack but did not make the information public." If true, that is pretty unfortunate…"
* http://www.avertlabs.com/research/blog/?p=95

:(