New Attack on Microsoft's PowerPoint
Just days after patching four bugs in PowerPoint, Bob McMillan of IDG News Service tells us that Microsoft is warning of a new attack targeting its presentation software.
"We?ve been made aware of proof of concept code published publicly affecting Microsoft Office 2003 PowerPoint," Microsoft Security Program Manager Alexandra Huft wrote in a blog posting. "The reported proof of concept may allow an attacker to execute code on a user?s machine by convincing them to open a specially-crafted PowerPoint file." Huft said that Microsoft is not aware of any attacks that take advantage of the bug, but with code now in circulation on public Web sites like Securitydot.net, the attack is easily available to attackers.
Security vendor Secunia rates the flaw as highly critical because it could be exploited to gain accessed to a fully patched Windows system.