Hackers to target Windows, PowerPoint
Summary
Microsofts massive update - a record-tying 13 separate security bulletins that patched 26 vulnerabilities - gives attackers all kinds of ways to compromise machines and hijack PCs. TippingPoints Zero Day Initiative (ZDI) - one of the two major bug bounty programs in the US - reported information about two of the six PowerPoint flaws to Microsoft. MAPP (Microsoft Active Protection Program) provides technical information about the vulnerabilities it plans to patch to vetted security software developers prior to the release of those updates. "It should be a priority for customers who have standalone installations of the PowerPoint Viewer 2003 to migrate to supported releases to prevent potential exposure to vulnerabilities," the companys accompanying bulletin read. Every researcher contacted today by Computerworld tapped MS10-013, which described a vulnerability in DirectShow, a component of Windows DirectX graphics infrastructure, as worth careful watching.