Zero-Day vulnerability found in PowerPoint 2003
October 15th, 2006 . by joe
This type of story is happening more and more lately. For those who are not aware, Microsoft is only willing to release security patches once per month, except for cases where the patch plugs a DRM hole. Because of this fact, hackers have started to release zero-day attacks a day or two after the monthly batch of security patches are released. This strategy guarantees that they can have their way with your machine for a full month before Microsoft patches the hole. This newest vulnerability is not thought to be as bad but it is being released on this same schedule.
Just days after Microsoft issued a record 26 patches, including 16 for Office, on Friday Symantec confirmed that just-released exploit code attacks a new, zero-day vulnerability in the PowerPoint presentation software.
According to Symantec’s alert, the exploit triggers a crash of PowerPoint. “It does not appear that the vulnerability can be leveraged to execute code, however the possibility has not been conclusively eliminated,” said Symantec to customers of its DeepSight threat system. “[We have] tested the exploit and it is confirmed to work as advertised.” Danish vulnerability tracker Secunia rated the threat as “highly critical,” its second-highest warning rank.

Posted in