News

Tuesday's Patch Will Target PowerPoint Security

Microsoft plans to roll out only one "critical" patch on Tuesday, affecting PowerPoint, for its May security update.

This update will be like a slide show that IT pros have seen before. It comes one month after a zero-day PowerPoint remote code execution vulnerability came to light for which the software giant issued a security advisory.

In that April security advisory, Redmond indicated that it was only "aware of limited and targeted attacks that attempt to use this vulnerability." Moreover, the advisory applied only to older Microsoft Office versions up through Office 2003.

With May's patch release coming up, the company apparently isn't taking any chances. This fix will apply to Microsoft Office 2000 and Office 2003, as well as Office XP and 2007 Microsoft Office systems.

At a more granular level, the patch touches on PowerPoint Viewer 2003 Service Pack 3, PowerPoint Viewer 2007 SP1 and SP2, and all versions of Microsoft Office Compatibility Packs for Word, Excel, and PowerPoint 2007 file formats.

The new PowerPoint security flaw has been described as "extremely critical" by independent software security vendors, such as Denmark-based Secunia, which provides an alert here.

Redmond says the patch "may" require a restart.

As usual, Microsoft refers those interested in nonsecurity updates delivered through Windows Update, Microsoft Update and Windows Server Updates to this Knowledgebase link.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

comments powered by Disqus

Featured

  • VS Code 1.125 Adds Copilot Spend Meter After Billing Shock

    VS Code 1.125 adds in-editor visibility into additional Copilot budget usage as GitHub's AI-credit billing model continues to draw developer scrutiny.

  • TypeScript 7.0 RC Moves Microsoft's Go Rewrite Into the Mainline Compiler

    Microsoft's Go-based TypeScript rewrite has reached Release Candidate status, moving from a separate native-preview package into the regular TypeScript npm package while leaving some ecosystem-facing API work for TypeScript 7.1 or later.

  • Microsoft Highlights Visual Studio Live! Event Lineup and Longtime Developer Community Role

    A Microsoft MVP Blog post on Visual Studio Live!'s longevity arrives as the 2026 conference series continues with upcoming stops at Microsoft HQ, San Diego and Orlando.

  • Using Local AI to Cut Copilot Usage-Based Billing Shock

    After being gobsmacked by the new billing plan using almost all my monthly credits in one or two days, I tried pushing some Copilot-style coding work onto local models in VS Code. What I found was less "free AI" and more "pick your pain": cloud charges on one side, heavy local resource use and long waits on the other.

Subscribe on YouTube