New 0-day Exploits Using Microsoft PowerPoint Files
From the Threat Research & Response Blog via bhandler:
The Microsoft Security Response Center has released Advisory 969136 today about a vulnerability in Microsoft Office PowerPoint which is being exploited in the wild. Office 2000, Office XP, Office 2003 and Mac Office are vulnerable however the latest version, Office 2007, is not.
So far we’re aware of several distinct exploit files which have been used. They all seem to be used only in targeted attacks and therefore the number of affected customers is very low.
Some “workarounds” can be found here:
TechNet: Investigating the new PowerPoint issue
BOTTOM LINE: Don’t open a “joke” that comes in the form of a PowerPoint presentation - especially from people that don’t normally send you PowerPoint presentations?
New 0-day Exploits Using PowerPoint Files
The Microsoft Security Response Center has released Advisory 969136 today about a vulnerability in Microsoft Office PowerPoint which is being exploited in the wild. Office 2000, Office XP, Office 2003 and Mac Office are vulnerable however the latest version, Office 2007, is not. The Microsoft SRD blog provides more details about the how to protect your environment from the vulnerability.
So far we’re aware of several distinct exploit files which have been used. They all seem to be used only in targeted attacks and therefore the number of affected customers is very low. Here’s a diagram that demonstrates how such an attack happens:

ppt virus
We are also releasing today a generic signature to protect our customers against these exploits. Its name is Exploit:Win32/Apptom.gen. Basically, access to such exploit files is blocked if a Windows Live OneCare user or a Forefront Client Security user tries to open them. This new signature is included in definition update version 1.55.975.0 or higher.
http://www.microsoft.com/security/portal/SearchResults.aspx?query=Exploit%3AWin32%2FApptom.gen
Leave a Reply