PowerPoint Version of (just patched) Office Zero-Day Spotted
Tuesday February 13, 2007 at 9:08 pm CST
Posted by Craig Schmugar
Earlier today Symantec posted a description for Trojan.PPDropper.G. The vulnerability mentioned in the description has been assigned CVE-2007-0913. SANS added it to their missing Microsoft patches table.
However, McAfee Avert Labs’ testing shows this issue was patched today in MS07-015 along with the Office Zero-Day reported by McAfee on February 2 (CVE-2007-0671). This testing suggests Trojan.PPDropper.G may in fact be a PowerPoint version of the Office zero-day exploit used in Exploit-MSExcel.h.
We will post an update when we have more definitive information.
Update Feb 14, 2007
Microsoft has confirmed that this is patched in MS07-015 and related to CVE-2007-0671.

February 14th, 2007 at 6:33 am
[…] Trackback […]
November 17th, 2007 at 10:07 am
There is something of a mystery here… MS07-015 clams to patch CVE-2007-0671 and CVE-2006-3877 - not CVE-2007-0913. At the same time, the malware that Symantec calls “Trojan.PPDropper.G” (and which McAfee’s scanner calls “Exploit-PPT.g”) most definitely does *not* contain CVE-2006-3877. So, CVE-2006-3877 and CVE-2007-0913 are not one and the same thing.
The only explanation is that MS07-015 has patched more than the two vulnerabilities it claims to have patched. Unfortunately, this still leaves unclear what exactly CVE-2007-0913 is. (I have a good understanding of what CVE-2007-0671 and CVE-2006-3877 are.) Microsoft’s claim that “it is related to CVE-2007-0671″ should be taken with a pinch of salt. Trust me, I *know* what kind of corruption CVE-2007-0671 uses in Excel files and that kind of corruption is most definitely *not* present in the equivalent PowerPoint records in the sample that is supposed to contain CVE-2007-0913.
As a side note, I’ve seen at least 8 other samples in Symantec’s monthly collections, all of them - PowerPoint files 1,933,824 bytes long (like the original), all of them having a very similar structure (and probably all of them containing CVE-2007-0913) but none of them detected by McAfee’s scanner.
December 17th, 2007 at 11:20 pm
OK, Peter Ferrie from Symantec figured out what CVE-2007-0913 is. Yep, it’s different from CVE-2006-3877 and CVE-2007-0671 (as I expected, Microsoft’s information is crap) and it was fixed by MS07-015. The other samples I mentioned indeed contain this exploit.