This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

PPT "exploit" on the Web

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Patch Tuesday Often Becomes Exploit Thursday
- http://blog.washingtonpost.com/securityfix…t_thursday.html
October 12, 2006
"…Today, less than 48 hours after Microsoft released a record number of security updates, comes the release of exploit code for yet another Office flaw, this one apparently targeted at PowerPoint files in Office 2003 (no, I'm not going to link to the site hosting the exploit code). As I've noted before, the Patch Tuesday/Exploit Wednesday (or Thursday) phenomenon gives bad guys the maximum amount of time to use exploits in the wild before Microsoft gets around to its next patch cycle… Regarding the Office exploit revealed today, a Microsoft spokesperson said the company "is investigating new public reports of a possible vulnerability in Microsoft Office 2003. Microsoft is not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time. Microsoft will continue to investigate the public reports to help provide additional guidance for customers as necessary.""

:ph34r:
FYI…

- http://blogs.technet.com/msrc/archive/2006…powerpoint.aspx
October 12, 2006 11:40 PM
"…We’ve been made aware of proof of concept code published publicly affecting Microsoft Office 2003 PowerPoint. We are currently investigating this report. The reported proof of concept may allow an attacker to execute code on a user’s machine by convincing them to open a specially-crafted PowerPoint file. We are not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time…" <_<

:ph34r:
FYI…

- http://secunia.com/advisories/22394/
Release Date: 2006-10-13
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
…According to Microsoft, the vulnerability may allow execution of arbitrary code. The vulnerability is reported in Microsoft PowerPoint 2003. Other versions may also be affected.
Solution: Do not open untrusted Office documents.
Original Advisory: Microsoft:
http://blogs.technet.com/msrc/archive/2006…powerpoint.aspx …"

:ph34r:
FYI…

- http://preview.tinyurl.com/yjnxne
November 10, 2006 10:28 PM
"…The short story is that this issue turned out to not be exploitable for remote code execution. It was a PowerPoint crashing bug, -not- a PowerPoint security vulnerability. The PowerPoint team has developed a fix for this bug and it will go into the next available ship vehicle for PowerPoint…"

.