Skip to main content

Criminals are using the Windows Object Linking Interface in Powerpoint to install malware

posted onAugust 16, 2017
by l33tdawg

Cyber criminals are using Microsoft PowerPoint to install malware. The Windows Object Linking Embedding (OLE) interface is the technology that allows exporting part of a document with a different editing application than the original. According to a report from Trend Micro (via Neowin), users are exploiting the use with PowerPoint slideshows.

These PowerPoint slideshows come in the form of an email and in the more recent cases, Neowin mentions that they come as attachments labeled shipping details. On closer inspection, the PPSX file from PowerPoint is just a playback  of the slideshow and opening it displays ‘CVE-2017-8570’.

But what’s happening behind the scenes is the problem. The CVE-2017-0199 Remove Code Execution vulnerability will open up to the exploit and run a process to download ‘logo.doc’ to the user’s computer. That document then runs a command to download ‘RATMAN.exe’ which can make a connection to a Command and Control server.

Source

Tags

Security

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Simplenews subscription

Stay informed - subscribe to our newsletter.
The subscriber's email address.
Keeping Knowledge Free for Over a Decade

Copyright © 2018 Hack In The Box. All rights reserved.

36th Floor, Menara Maxis, Kuala Lumpur City Centre 50088 Kuala Lumpur Malaysia
Tel: +603-2615-7299 Fax: +603-2615-0088