PT-2006-4324 · Microsoft · Office Powerpoint
Arnaud Dovi
·
Published
2006-10-10
·
Updated
2018-10-30
·
CVE-2006-3435
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office PowerPoint versions in Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac
Description
The issue arises from the improper parsing of the slide notes field in a document, allowing remote user-assisted attackers to execute arbitrary code via crafted data in this field. This triggers an erroneous object pointer calculation that uses data from within the document. A remote code execution vulnerability exists when PowerPoint parses a file that includes a malformed object pointer.
Recommendations
For Microsoft Office PowerPoint versions in Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac, consider avoiding the use of crafted or potentially malicious files until a patch is available.
As a temporary workaround, restrict access to potentially malicious PowerPoint files to minimize the risk of exploitation.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Powerpoint