Windows Zero Day

Posted 21 Oct 2014

Microsoft has published an advisory for a Windows 0 dayexploit. The exploit is related to the Object Linking and Embedding (OLE) functionality in Windows. OLE functions allow files or data from one file to be embedded into another document or file. A Windows users must open a malicious file to be impacted.  The file can be received from any vector such as a website link, an email attachment or a file share. The exploits impacts the latest versions of Windows, and no patch is available at this time. The advisory does include some workaround steps including a Fix-It solution to mitigate the risk of the attack. User Account Control (UAC) can also help.

