myITforum.com

Welcome to myITforum.com Sign in | Join | Help
in Search

Harry Waldron at myITforum.com

Sharing Security Developments, and Best Practices for corporate and home users

Powerpoint unpatched vulnerability - new variant

These are mostly being spammed by email and should not be prevelant in the wild.  Users should be cautious with all Powerpoint documents recieved in email.

Powerpoint unpatched vulnerability - new variant
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EAY
http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-072712-3824-99

QUOTE: When executed, it exploits a vulnerability in Microsoft Powerpoint wherein a specially crafted document can cause the application to drop and execute an embedded EXE file in the Windows folder.  Once it successfully exploits the mentioned vulnerability, it is able to execute a shell code which, in turn, runs the embedded .EXE file. This .EXE file is detected by Trend Micro as TROJ_AGENT.CZW.

Also, Trend has added detection today for a new Powerpoint POC crash exploit that's most likely related to this overall vulnerability:

New PowerPoint POC Crash exploit
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FPPCRASH%2EA

Comments

No Comments
Powered by Community Server (Commercial Edition), by Telligent Systems