PT-2006-4324 · Microsoft · Office Powerpoint

Arnaud Dovi

·

Published

2006-10-10

·

Updated

2018-10-30

·

CVE-2006-3435

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office PowerPoint versions in Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac
Description The issue arises from the improper parsing of the slide notes field in a document, allowing remote user-assisted attackers to execute arbitrary code via crafted data in this field. This triggers an erroneous object pointer calculation that uses data from within the document. A remote code execution vulnerability exists when PowerPoint parses a file that includes a malformed object pointer.
Recommendations For Microsoft Office PowerPoint versions in Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac, consider avoiding the use of crafted or potentially malicious files until a patch is available. As a temporary workaround, restrict access to potentially malicious PowerPoint files to minimize the risk of exploitation.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-3435

Affected Products

Office Powerpoint