PowerPoint hit by new zero-day exploit

By

Microsoft warns flaw could allow remote code execution.

PowerPoint hit by new zero-day exploit
A new vulnerability in Office has emerged just two days after Microsoft's monthly patch release on 10 October. 

The Microsoft Security Response Centre warned in a blog posting that a new vulnerability in PowerPoint could allow remote code execution. 

The vulnerability has only been presented as proof-of-concept code meaning that, although a security flaw has been found, there is no evidence of any exploit code or active attacks taking place.

Microsoft issued four patches on Tuesday for vulnerabilities in Office that allowed for remote execution of code.

In one case, attackers were using specially crafted files to target another vulnerability in PowerPoint in order to gain access to a system and run malware.

The US Computer Emergency Readiness Team urges users to avoid opening attachments in unsolicited emails and to scan all attachments with an antivirus program before running the code.
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

"VoidProxy" PhishKit targets Google and Microsoft users

"VoidProxy" PhishKit targets Google and Microsoft users

First npm worm "Shai-Hulud" released in supply chain attack

First npm worm "Shai-Hulud" released in supply chain attack

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Log In

  |  Forgot your password?