03 Apr 2009
Microsoft has warned of a vulnerability in PowerPoint that could enable a hacker to gain remote control of a PC.
A security advisory from the company offers advice on how to guard against the exploit, and said that attacks have already been seen in the wild.
"Microsoft is investigating new reports of a vulnerability in Microsoft Office PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file. At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability."
The warning should also serve as a reminder to office workers to not blindly open attachments. The nature of the vulnerability means that an attacker would have to convince users to visit a particular web site, and then persuade them to open the specially-crafted PowerPoint file.
Microsoft reminded companies that the enabler for many such attacks is often the human element.
"The vulnerability cannot be exploited automatically through email. For an attack to be successful a user must open an attachment that is sent in an email message," the security alert said.
Microsoft hinted at the possibility of a patch, suggesting that it could be included in its regular Patch Tuesday release, or as an out of cycle release, depending on customer needs.
In the meantime Microsoft offered a few workarounds. "Do not open or save Office files that you receive from un-trusted sources, or that are received unexpectedly from trusted sources," the firm warned.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Solution Architect / Technical Project Manager / Corporate...
Tier 1 Investment Bank seeks an Administrator with an...
Are you a proven agile test engineer that wants to work...
A leading global organisation seeks a Lead Project Planner...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?