CVE-2017-0199 was originally a zero-day remote code execution vulnerability that allowed attackers to exploit a flaw that exists in the Windows Object Linking and Embedding (OLE) interface of Microsoft Office to deliver malware. It is commonly exploited via the use of malicious Rich Text File (RTF) documents, which was used by the DRIDEX banking trojan discovered earlier this year.
Post from: Trendlabs Security Intelligence Blog - by Trend Micro
CVE-2017-0199: New Malware Abuses PowerPoint Slide Show