Microsoft discloses zero-day flaw, publishes quick fix

Microsoft has published a temporary fix for a new zero-day flaw that affects nearly all versions of Windows and is currently being exploited via PowerPoint.

The flaw affects all Windows releases except Windows Server 2003, the company wrote in an advisory Tuesday. It can be exploited if a user is coaxed into opening a malicious Office file containing an OLE (object linking and embedding) object. OLE can allow a user to edit a PowerPoint file from within a Word document, for example.

“At this time, we are aware of limited, targeted attacks that attempt to exploit the vulnerability through Microsoft PowerPoint,” the company said.

To read this article in full or to leave a comment, please click here

Read more: Microsoft discloses zero-day flaw, publishes quick fix

Story added 22. October 2014, content source with full text you can find at link above.