Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 28th, 2006, 09:36 PM
Caine Caine is offline
Regular Poster
 
Join Date: Nov 2005
Posts: 63
Default PowerPoint 0day Exploit (9-27-06)

http://www.nist.org/news.php?extend.173
Quote:
McAfee is warning that a new 0day PowerPoint exploit has been seen in the wild. Currently being used in targeted attacks. Remote code execution possible. Microsoft may have quietly added protection for it to their own antivirus program without alerting the security community.

Hopefully the antivirus programs will have signatures for this soon so unless you are the "target" in the "targeted attacks" you should be ok. The only way to suffer the exploit is to launch the file. So if you receive a PowerPoint 'ppt' file you are not expecting you should not open it. Office 2000, Office XP, and Office 2003 are affected and reports are indicating that the Mac versions are also vulnerable

Is this covered by NOD32?
  #2  
Old September 29th, 2006, 04:10 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: PowerPoint 0day Exploit (9-27-06)

Yes, it is now Caine!
See here
Definition is highlighted: W97M/TrojanDropper.Lafool.F
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #3  
Old September 29th, 2006, 08:24 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: PowerPoint 0day Exploit (9-27-06)

hmm...it seems they've added it actually today.

I think this are the right definitions: PP97M/TrojanDropper.PPDrop.F, PP97M/TrojanDropper.PPDrop.NAA (2), PP97M/TrojanDropper.PPDrop.NAB
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #4  
Old September 29th, 2006, 12:57 PM
Caine Caine is offline
Regular Poster
 
Join Date: Nov 2005
Posts: 63
Default Re: PowerPoint 0day Exploit (9-27-06)

Nice one! Thanks for that pykko.

Is this sort of behaviour common with Microsoft? Pretty sneaky carry-on altogether.
  #5  
Old September 30th, 2006, 03:13 PM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: PowerPoint 0day Exploit (9-27-06)

Well, generally there are many exploits on MS products because many use them and hackers try to exploit evry little bug from them.
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #6  
Old October 1st, 2006, 08:15 PM
Caine Caine is offline
Regular Poster
 
Join Date: Nov 2005
Posts: 63
Default Re: PowerPoint 0day Exploit (9-27-06)

True that, but still though it's not so much the volume of exploits that MS inevitably have to battle with. It's the way they fixed up their own Security software defs and said nothing to the others. That's the bit that bugs me. Aw well, worrying over nothing since it's not an issue now.
  #7  
Old October 2nd, 2006, 07:32 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: PowerPoint 0day Exploit (9-27-06)

Quote:
Originally Posted by Caine
It's the way they fixed up their own Security software defs and said nothing to the others.
Well, yes, basically if a new dangerous threat appear AV companies should be willing to exchange defs.
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:35 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums