-
Another PowerPoint 0day hole
The Microsoft Security Response Center just reported that they’ve encountered yet another new PowerPoint 0day security hole. This one’s a little different: the report says that there is publicly available “Proof of Concept” code posted on the Internet that takes advantage of the hole.
The only PoC code I’ve seen (at milw0rm) crashes PowerPoint – it’s a so-called “Denial of Service” attack – but it doesn’t seem to run arbitrary code.
I haven’t seen any other details, but it’s likely that this exploit was held until the day after Patch Tuesday, to maximize the length of time it’ll be usable – another Wacked-out-Wednesday sploit. The milw0rm code is dated Thursday.
Will keep you posted.