Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft Security Advisory released on OLE bug vulnerability in Microsoft Office files – onmsft.com

Microsoft Security Advisory released on OLE bug vulnerability in Microsoft Office files – onmsft.com

Staff Writer Staff Writer
October 22, 2014
1 min read

Microsoft Security Advisory released on OLE bug vulnerability in Microsoft Office files

\

In the last Patch Tuesday, there was an update targeting a bug in the OLE that allowed remote code execution. We had assumed that it was fixed, but it seems to be a more complex issue than we anticipated. Microsoft has released Security Advisory 3010060 concerning this bug, along with a one-click ‘Fix it’ solution.

\

This vulnerability is in every supported release of Microsoft Windows, besides Windows Server 2003. It is found in maliciously-crafted Microsoft Office files (the attackers were found using PowerPoint files) with an OLE object. OLE, which stands for Object Linking and Embedding, can be useful in cases such as linking an Excel file in a PowerPoint so you only have to edit the data in one place.

\

Embedded Excel Object in PowerPoint

\

While attacks have been very limited and specific, if you are worried about the vulnerability, there are a few things you can do.

\

The first is the ‘Fix it’ solution (click here), which patches this vulnerability for Microsoft PowerPoint on both 32-bit and 64-but editions of Microsoft Windows — except 64-bit PowerPoint on 64-bit Windows 8 and 8.1. Additionally, Microsoft has stated this is a vulnerability with all Office files, so if the attackers switch away from PowerPoint files, this isn’t of much help.

\

The second thing you can do, and everyone should, is not open files from sources you don’t trust. Even if it is from a trusted source, use common sense as the attackers may have tricked your friends.

\

If this isn’t comforting, there are two other solutions. Since this vulnerability gives an attacker with the same user rights as the current user, there are differences in how vulnerable you can be initially.

\

The last two solutions are to enable User Account Control, and deploy the Enhanced Mitigation Experience Toolkit 5.0 and configure Attack Surface Reduction.

\

You can find out how to enable the last two solutions, as well as other suggestions and details, by reading the advisory yourself (here). Microsoft is, of course, monitoring the exploit and working on a security update.

\

Share This Post:

Share this article:
Tags:
Security
Previous Article Windows 10 Build 9860 Includes New Notification Center, PC Settings Changes And More (video) – onmsft.com Next Article Watch the Sunset Overdrive launch trailer, will be released with a white Xbox One on the 28th – onmsft.com

Related Articles

Analyst Says Fortnite’s “Forever Game” Era Is Ending After Epic Games Layoffs

April 6, 2026
Intel’s Advanced Packaging Business Grows Fast as AI Companies Look Beyond TSMC

Intel’s Advanced Packaging Business Grows Fast as AI Companies Look Beyond TSMC

April 6, 2026

Samsung Could Launch Four Galaxy S27 Models With New Pro Variant

April 6, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Analyst Says Fortnite’s “Forever Game” Era Is Ending After Epic Games Layoffs
  • Intel’s Advanced Packaging Business Grows Fast as AI Companies Look Beyond TSMC
  • TSMC Earnings Call to Address Middle East Crisis and Supply Chain Risks
  • Samsung Could Launch Four Galaxy S27 Models With New Pro Variant
  • Leaker Says PlayStation 6 Won’t Slip Past 2028 Due to AMD Progress

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Analyst Says Fortnite’s “Forever Game” Era Is Ending After Epic Games Layoffs
  • Intel’s Advanced Packaging Business Grows Fast as AI Companies Look Beyond TSMC
  • TSMC Earnings Call to Address Middle East Crisis and Supply Chain Risks
  • Samsung Could Launch Four Galaxy S27 Models With New Pro Variant
  • Leaker Says PlayStation 6 Won’t Slip Past 2028 Due to AMD Progress

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy