Hacker News new | ask | show | jobs
by personZ 4263 days ago
The exploit seems to leverage PowerPoint files which are generally considered safe, and thus are allowed through mail systems and most normal good-practice behaviors. It uses a sideband exploit that allows PowerPoint to download and execute arbitrary content via a system service.

That is absolutely an exploit, similar to if I linked to an imgur jpeg that actually ran a trojan on your machine.