Security Management
Published on Security Management (http://www.securitymanagement.com)
Microsoft Issues Critical Patch for PowerPoint
By Matthew Harwood
Created 05/13/2009 - 12:49



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
05/13/2009
By Line: 
By Matthew Harwood
Teaser: 

Microsoft released patches yesterday for its popular PowerPoint program for PCs due to a vulnerability that would allow a hacker to gain complete control of a system, although Apple users will have to wait a little longer for their patch.

Microsoft released patches yesterday for its popular PowerPoint program for PCs due to a vulnerability that would allow a hacker to gain complete control of a system [1], reports Reuters.

Microsoft defined the threat as "critical" -- the most severe on the scale by which it ranks vulnerabilities to its software.

Hackers are seeking to exploit the vulnerability in PowerPoint by persuading the intended victim to open a tainted PowerPoint file -- that they either download from a Website or receive in an email, according to Symantec Corp, the world's top maker of security software.

According to Microsoft's security bulletin [2]:

This security update resolves a publicly disclosed vulnerability and several privately reported vulnerabilities in Microsoft Office PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Apple users of the program are also vulnerable, but a patch does not exist yet for their computers. Microsoft ensured Apple users that one is in the works. It is the first time Microsoft has released a patch that did not plug the holes in every affected version, reports another article from Reuters [3].

Jonathan Ness, an engineer with the Microsoft Security Response Center (MSRC), wrote on the MSRC Security Research and Defense blog [4] that "None of the [PowerPoint] exploit samples we have analyzed will reliably exploit the Mac version so we didn’t want to hold the Windows security update while we wait for Mac packages."

Reuters also warns that older versions of PowerPoint, especially the 2000 version, is more susceptible to attack.

Related Resources: 

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/microsoft-issues-critical-patch-powerpoint-005627

Links:
[1] http://www.reuters.com/article/technologyNews/idUSTRE54B6H820090512
[2] http://www.microsoft.com/technet/security/bulletin/ms09-may.mspx
[3] http://www.reuters.com/article/idgSmallBusiness/idUS202218302520090512
[4] http://blogs.technet.com/srd/archive/2009/05/12/ms09-017-an-out-of-the-ordinary-powerpoint-security-update.aspx