PT-2008-1775 · Microsoft · Powerpoint Viewer 2003+1

Ruben Santamarta

·

Publicado

2008-08-12

·

Atualizado

2018-10-12

·

CVE-2008-0120

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft PowerPoint Viewer 2003
Description The issue allows remote attackers to execute arbitrary code via a specially crafted PowerPoint file, potentially leading to memory corruption. This can be exploited by creating a malicious PowerPoint file that could be sent as an email attachment or hosted on a compromised website. If successfully exploited, an attacker could gain complete control of the affected system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights. The impact may be less severe for users with limited user rights.
Recommendations For Microsoft PowerPoint Viewer 2003, consider avoiding the use of specially crafted PowerPoint files until a fix is available. As a temporary workaround, restrict access to potentially malicious files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0120

Produtos afetados

Powerpoint Viewer 2003
Office Powerpoint