neox Posted October 25, 2014 Report Posted October 25, 2014 This recent exploit (dubbed “Sandworm”) took advantage of a vulnerability in which a specially crafted OLE object could allow remote code execution. In the case of the live sample exploit PPSX file I examined, it automatically downloaded the payload from a remote SMB share. I won’t rehash much of the details that others have covered but if you want to read more, here are some resources: Microsoft Security Bulletin: https://technet.microsoft.com/en-us/library/security/ms14-060.aspx Original Discovery by iSightPartners: http://www.isightpartners.com/2014/10/cve-2014-4114/Other Good write-up on D.UIJN.NL: d.uijn.nl | that's me!videohttp://www.securitysift.com/wp-content/uploads/2014/10/ms14_060.mp4source:Windows OLE RCE Exploit MS14-060 (CVE-2014-4114) - Sandworm - Security SiftSecurity Sift Quote