Concern as Microsoft fails to patch PowerPoint flaw

Powered by SC Magazine
 

Security experts are expressing concern at Microsoft's failure to patch a flaw in PowerPoint that is already being exploited by malware writers.

The flaw is being used in attacks at the moment and many were expecting a patch at the last Patch Tuesday but to date there has been no sign of the fix.

“This PowerPoint exploit is in the wild right now,” said Graham Cluley, senior technology consultant at Sophos.

“It comes in the form of a presentation showing naked Japanese girls bathing in rockpools, or as an IQ test, to lure the user in. We're hoping Microsoft will patch this soon.”

He said that so far the exploit was being used in a targeted fashion but there was serious concern that it would be spammed out as part of a botnet recruitment drive.

The issue comes as more and more security experts are expressing concern at the levels of application vulnerabilities and the lack of patching and updating.

“It's a problem for IT departments as they are often stretched for resources and there are many applications to patch,” said Niels Henrik Rasmussen, founder of vulnerability researchers Secunia.

He pointed out that both his own research and the latest Microsoft Security Intelligence Report showed that application flaws were becoming a more important issue for security than operating system flaws.

Copyright ©v3.co.uk


Concern as Microsoft fails to patch PowerPoint flaw
 
 
 
Top Stories
Windows 10 lands in Australia
Campaign to get business to upgrade kicks off.
 
NSW to build its own myGov
Service NSW digital profiles available by September.
 
Android bug leaves a billion phones open to attack
Hackers only need phone number to target devices.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
The 5 Windows 10 privacy issues you should be aware of
Jul 31, 2015
There are a few unsettling details when it comes to Windows 10 privacy
Windows 10 is here! (For some)
Jul 29, 2015
Delivery of the free upgrade versions of Windows 10 began today - have you got yours yet?
Microsoft reveals Microsoft Send, a new enterprise chat app to rival Slack
Jul 27, 2015
Microsoft Send is MSN Messenger for grownups, and you could be using it at work very soon
Developers offered $500,000 grants to find HoloLens uses
Jul 8, 2015
Can augmented-reality end up in business?
Microsoft Tossup: The planning app for unorganised groups of friends
Jul 8, 2015
App allows friends to research venues, vote on plans and chat. And depending on how you run your ...
Latest Comments
Polls
Should law enforcement be able to buy and use exploits?



   |   View results
Yes
  14%
 
No
  51%
 
Only in special circumstances
  17%
 
Yes, but with more transparency
  18%
TOTAL VOTES: 782

Vote