Microsoft Confirms PowerPoint Zero-Day Attack

From software to hardware, breakthough to disaster, it all belongs here!

Moderator: CricketMX Forum Moderators

Post Reply
User avatar
moongirl
Moderator
Moderator
Posts: 19049
Joined: Mon Jan 12, 2004 8:07 am

Microsoft Confirms PowerPoint Zero-Day Attack
07.14.06
By Ryan Naraine

For the third time in two months, a zero-day vulnerability in a widely used Microsoft Office software application is being used in targeted hacker attacks.

The latest attack exploits a previously undocumented flaw in Microsoft PowerPoint, the ubiquitous presentation program used by millions of users around the world.

The attack comes just days after Microsoft's July Patch Tuesday and closely mirrors the situation in June when a zero-day Excel attack was discovered 24 hours after Patch Day.

Virus hunters at Symantec linked the zero-day attack to a Trojan horse program called Trojan.PPDropper.B that arrives via e-mail from a Gmail address.

The subject line of the mail and the .ppt file-name are in Chinese characters, suggesting that the attacks are emanating from—and attacking targets—in the Far East.

If the PowerPoint attachment is opened, the Trojan drops and executes a variant of Backdoor.Bifrose.E, a keystroke logger that is used to steal sensitive information and send it back to a remote server controlled by malicious hackers.

The Trojan also injects a malicious routine into the EXPLORER.EXE process that overwrites the malicious PowerPoint file with a new clean copy of the document.
http://www.pcmag.com/article2/0,1895,1989143,00.asp

Firms Wait for Microsoft Fix for Day Zero Powerpoint Flaw
Saturday, July 22, 2006
Experts at SophosLabs, Sophos's global network of virus, spyware and spam analysis centers, have advised companies to exercise care over which PowerPoint presentations their users open, as businesses wait for Microsoft to fix an unpatched PowerPoint vulnerability.

Microsoft has confirmed that a critical vulnerability exists in PowerPoint 2000, PowerPoint 2002 and PowerPoint 2003 which can allow malicious attackers to run unauthorized code on users' computers. According to the company, it is scheduled to issue a fix on Tuesday 8 August or earlier if required.

"PowerPoint is commonly used in the business environment for delivering corporate presentations. Hackers may attempt to trick workers into opening malicious PPT attachments that could exploit the flaw and install malware onto Windows computers," said Graham Cluley, senior technology consultant for Sophos. "Many have experienced the soul-destroying feeling of sitting through a far-too-long corporate presentation, but this critical flaw could deliver a far more serious case of 'Death by PowerPoint'."

Microsoft has published information about the vulnerability in an advisory on its website.

"Once a PC has been infected by a backdoor Trojan, hackers can gain access to the computer to spy, to steal, to plant further malicious software, or to launch spam and/or denial-of-service attacks. Many eyes will now be looking to Microsoft, to see how quickly they can release a critical security fix for their PowerPoint program," continued Cluley. "Everyone needs to exercise caution over which files they choose to open on their Windows PC."

Last week, Sophos experts warned of a malicious Chinese PowerPoint PPT file which contained exploit code that drops the Troj/Edepol-C keylogging Trojan horse onto users' computers.

The PowerPoint presentation secretly drops a Trojan horse onto computers.

Sophos has been protecting against the Troj/Edepol-C Trojan horse dropped by the Microsoft PowerPoint file since 14:01 GMT, Friday 14 July, but warns that hackers could exploit the PowerPoint vulnerability to spread new Trojan horses.

Sophos recommends companies put in place a consolidated solution to defend against viruses, spyware and spam, and ensure that it is automatically updated as new threats emerge.
http://tinyurl.com/qk9n7
http://www.infozine.com/index.php
Image
That's not the man in the moon...that's me ;)
Post Reply