PT-2006-4324 · Microsoft · Office Powerpoint
Arnaud Dovi
·
Publicado
2006-10-10
·
Atualizado
2018-10-30
·
CVE-2006-3435
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office PowerPoint versions in Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac
Description
The issue arises from the improper parsing of the slide notes field in a document, allowing remote user-assisted attackers to execute arbitrary code via crafted data in this field. This triggers an erroneous object pointer calculation that uses data from within the document. A remote code execution vulnerability exists when PowerPoint parses a file that includes a malformed object pointer.
Recommendations
For Microsoft Office PowerPoint versions in Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac, consider avoiding the use of crafted or potentially malicious files until a patch is available.
As a temporary workaround, restrict access to potentially malicious PowerPoint files to minimize the risk of exploitation.
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Office Powerpoint