MS Patches PowerPoint Hole

Posted by on May 12th, 2009 and filed under Security, Software. You can follow any responses to this entry through the RSS 2.0. You can skip to the end and leave a response. Pinging is currently not allowed.

word-sell-power-point.JPG

Microsoft today released a patch for the hole found in PowerPoint. Sadly the patch doesn’t cover Mac or the older Works Suite. CNET has some more:

Without the patch, the vulnerability can be exploited by getting a person to open a PowerPoint file rigged for the attack, Microsoft has said. When the file is opened, PowerPoint will access an invalid object in memory. That then allows an attacker to remotely execute code on the system.

The fix was released as part of the company’s regularly scheduled monthly Patch Tuesday.

Microsoft said that the vulnerability is not rated critical for PowerPoint 2002 and later versions because they prompt a user before opening a document, meaning that the vulnerability “requires more than a single user action to complete the exploit.”

Yeah ok, this guy obviously works in an environment of smart users. Let me tell you about the general work force, a prompt asking if they are sure if they want to open the file means nothing. A chance to see cute cats doing something dumb is just too hard for most to pass up.

(Via CNET)

Leave a Reply