The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file that contains an OLE object.
Microsoft is aware of a vulnerability affecting all supported releases of Microsoft Windows, excluding Windows Server 2003. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.
Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights. The attack requires user interaction to succeed on Windows clients with a default configuration, as User Account Control (UAC) is enabled and a consent prompt is displayed.
At this time, we are aware of limited, targeted attacks that attempt to exploit the vulnerability through Microsoft PowerPoint. We are actively working with partners in our Microsoft Active Protections Program (MAPP) to provide information that they can use to provide broader protections to customers. For information about protections released by MAPP partners, see MAPP Partners with Updated Protections.
Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.
Mitigating Factors:
Axarhöfði 14,
110 Reykjavik, Iceland