Unpatched PowerPoint Flaw Under Attack

執筆者
Ryan Naraine
Ryan Naraine
Published: Sep 27, 2006
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsofts summer-long struggle to lock down gaping holes in its Office software suite has once again escalated with the discovery of a new zero-day attack targeting PowerPoint users.

The Redmond, Wash., software maker confirmed reports from anti-virus vendors that another round of “extremely limited attacks” is exploiting a previously unknown PowerPoint vulnerability.

The e-mail-borne attack, which uses rigged .ppt attachments, is being used to plant a Trojan dropper on infected Windows machines.

According to an advisory from Symantec, the malicious file injects itself into several computer processes and uses rootkit techniques to hide its files and process.

It opens a back door and connects to Web sites hosted at the 6600.org and 9966.org domains, allowing a malicious hacker full control of the target machine.

The file names of the rigged PowerPoint files are “FinalPresentationF05.ppt,” and “2006-Jane.ppt,” according to Symantecs alert.

The tactics appear identical to a recent wave of zero-day PowerPoint exploits that experts believe are linked to corporate espionage in the Far East.

Symantec said the targeted attack could be used to perform network reconnaissance, search for files, download and upload files, create and remove folders, execute commands or update registry entries.

McAfee, an anti-virus software vendor in Santa Clara, Calif., said the exploit was aimed at “a single target,” further confirming that the recent exploits against Microsoft Office users are part of well-targeted attacks.

A spokesperson for Microsoft said the companys investigation has concluded that the vulnerability affects users of Microsoft Office 2000, Microsoft Office 2003 and Microsoft Office XP.

“In order for this attack to be carried out, a user must first open a malicious Microsoft PowerPoint document that is sent as an e-mail attachment or otherwise provided to them by an attacker,” the spokesperson said.

He said Microsoft is aware of an attack scenario that involves malware known as “Win32/Controlppt.W” and “Win32/Controlppt.X,” and has added detection and removal signatures to its free Windows Live OneCare safety scanner.

Advertisement

Check out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。