Sophos has posted a blog entry about malicious documents that exploit the MS06-028 vulnerability. The vulnerability was patched three years ago.

If a user’s machine has been patched, he or she will get a warning that says that “Powerpoint was unable to display some of the text, images…” when he or she tries to open the file.

A brief flicker will occur on-screen before the first slide of the presentation shows up. The malicious documents are detected as Troj/ExpPPT-G.

Source: Sophos