Home > Security News > Trojan targets Microsoft PowerPoint flaw
Security News:
EMAIL THIS

Trojan targets Microsoft PowerPoint flaw

By Bill Brenner, Senior News Writer
13 Jul 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Update: A serious security hole affecting Microsoft PowerPoint is being attacked in the wild by a Trojan horse, Symantec Corp.'s DeepSight Threat Analysis Team warned late Wednesday.

In an email analysis to customers, the Cupertino, Calif.-based antivirus giant said it is investigating to see if the exploit is tied to the previously known Microsoft Excel style handling and repair remote code execution flaw, with PowerPoint simply being used as a new attack vector. The company has advised IT administrators to make sure regular antivirus updates are applied as it carries out its investigation.

In its advisory, the DeepSight team said it has confirmed reports of an in-the-wild attack being performed with a maliciously crafted Microsoft Office PowerPoint file. "These attacks are exploiting a previously unknown and currently unpatched vulnerability affecting PowerPoint, and possibly Microsoft Office in general," Symantec said.

The exploit arrives via email as a Microsoft PowerPoint document attachment, Symantec said. When a user launches the PowerPoint document, the vulnerability is triggered and attackers are then able to run malicious code on a victim's machine.

"The vulnerability occurs when PowerPoint handles a specially malformed .ppt file most likely exploiting an issue in the 'MSO.DLL' library file," Symantec said, adding that it has released definitions for the malicious code used in this attack. The malicious code has been identified as Trojan.PPDropper-B.

This glitch affects Powerpoint 2003 and possibly other versions, Symantec said.

A Microsoft spokesman Thursday said the Redmond, Wash.-based vendor is investigating the issue, and may issue a security advisory or a security update through its monthly patch release process if necessary.

"Microsoft is aware of extremely limited, targeted attacks exploiting this vulnerability," Microsoft said. "In order for this attack to be carried out, a user must first open a malicious PowerPoint document that is sent as an email attachment, posted to a Web site or otherwise provided to them by an attacker. On more recent versions of PowerPoint, opening the PowerPoint document out of email will prompt the user to be careful about opening the attachment."

In addition to keeping antivirus programs updated, Symantec said IT administrators can blunt the threat by:

  • Running all software as a non-privileged user with minimal access rights.

  • Deploying network intrusion detection systems (IDS) to monitor network traffic for malicious activity.

  • Not accepting or executing files from untrusted or unknown sources.

  • Not following links provided by unknown or untrusted sources.

  • Implementing multiple redundant layers of security.

    Security Wire Weekly

    For more on Microsoft's July security bulletins, listen to Qualys' Jonathan Bitle discuss the latest Microsoft Office flaws and fixes in this week's Security Wire Weekly podcast (.mp3).
    Microsoft was not immediately available for comment on the threat, which surfaced a day after the software giant released seven security updates, including one that fixed eight critical flaws in Microsoft Excel and additional flaws in Microsoft Office.

    Security experts have warned that not all known Office and Excel flaws were addressed Tuesday (.mp3).

    Tags: Securing Productivity ApplicationsNetwork Intrusion Detection (IDS)Malware, Viruses, Trojans and SpywareVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Securing Productivity Applications
    How to detect software tampering
    Adobe fixes 29 flaws in Acrobat, Reader
    Adobe warns of critical update for Reader, Acrobat 9.1.3
    Why should we place data files on a separate partition than the OS?
    Adobe updates ColdFusion, JRun, Flex
    Serious Adobe Flash flaw being exploited
    Adobe acknowledges serious Flash zero-day vulnerability
    Adobe issues security advisory for Flash zero-day flaw
    When to use the service features of the Metasploit hacking tool
    How to manage patches for Adobe

    Network Intrusion Detection (IDS)
    Preventing SQL injection attacks: A network admin's perspective
    Lifecycle of a network security vulnerability
    Best Intrusion Prevention and Detection Products
    Rogue AP containment methods
    SIMs tools and tactics for business intelligence
    IPS and IDS deployment strategies
    Know when you need IDS, IPS or both
    Trend Micro to acquire Third Brigade for virtualization, cloud security
    New product aims to control rogue applications that avoid firewalls
    How to perform a network forensic analysis and investigation
    Network Intrusion Detection (IDS) Research

    Malware, Viruses, Trojans and Spyware
    Schneier-Ranum Face-Off: Is antivirus dead?
    Modern malware, stealthy botnets, adapt quickly, expert says
    Computer worm infections up, scareware antivirus down, Microsoft says
    Web-based attacks skyrocket, pirating sites surge, security firms say
    Mini guide: How to remove and prevent Trojans, malware and spyware
    Kaspersky system analyzes malicious URLs on Twitter for malware
    Silon malware intercepts Internet Explorer sessions, steals credentials
    Breach forces payroll service provider PayChoice to shut down again
    RSA research underscores problem tracking cybercriminals
    Conficker analysis finds P2P coding limited, less sophisticated

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    sheepdip  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts