• MS PowerPoint Vulnerability Exposed
    Share
    |
  • By CXOtoday Staff, Apr 06, 2009 1317 hrs IST
  • Tags : Microsoft, vulnerability in MS Office PowerPoint, PowerPoint file, Office Document Open Confirmation Tool, Office 2000, Office XP

  • Microsoft has received reports of a vulnerability in MS Office PowerPoint that could allow remote code execution if a user opens a specially-crafted PowerPoint file.


    The company said it is investigating these reports and till now they are aware only of limited and targeted attacks that attempt to use this vulnerability. This security advisory was released on Thursday.


    In the advisory, Microsoft said any attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights. The vulnerability cannot be exploited automatically through e-mail. For an attack to be successful a user must open an attachment that is sent in an e-mail message.


    Users who have installed and are using the Office Document Open Confirmation Tool for Office 2000 will be prompted with 'Open', 'Save', or 'Cancel' before opening a document. The features of the Office Document Open Confirmation Tool are incorporated in Office XP and later editions of Office.


    Microsoft said it could release a solution through their monthly security update release process, or an out-of-cycle security update, depending on customer needs.


    Customers in the US and Canada who believe they are affected can receive technical support from security support or 1-866-PCSAFETY. There is no charge for support calls that are associated with security updates.


    International customers can receive support from their local Microsoft subsidiaries.




    More information about can be found at the International support website.


    Related Links

    Microsoft Office Excel Has Critical Flaw
    Protect Your Shared Documents

    'Software Piracy Benefits Nobody'

  • When you talk, we listen
  • Do you find CXOtoday useful?
    Advise us on how to make it better.
  • Advertisement  
  • Advertisement