Blog | G5 Cyber Security

Zero-Day Remote Code Execution Flaw Disclosed by Microsoft; Workarounds Issued

Microsoft has disclosed a Windows OLE zero-day remote code execution (RCE) vulnerability in PowerPoint and released a quick fix. The vulnerability impacts all Windows versions, except Windows Server 2003 and it is currently being exploited via malicious Office files that contain OLE objects. The OLE technology allows users to cross-edit documents within other editor, for example editing a PowerPoint file within the Word text editor. If exploited, the flaw could allow an attacker to gain the same rights as the active user and further infect the victims system.”]

Source: https://www.bitdefender.com/blog/hotforsecurity/zero-day-remote-code-execution-flaw-disclosed-by-microsoft-workarounds-issued/

Exit mobile version