PT-2008-1775 · Microsoft · Powerpoint Viewer 2003+1

Ruben Santamarta

·

Published

2008-08-12

·

Updated

2018-10-12

·

CVE-2008-0120

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft PowerPoint Viewer 2003
Description The issue allows remote attackers to execute arbitrary code via a specially crafted PowerPoint file, potentially leading to memory corruption. This can be exploited by creating a malicious PowerPoint file that could be sent as an email attachment or hosted on a compromised website. If successfully exploited, an attacker could gain complete control of the affected system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights. The impact may be less severe for users with limited user rights.
Recommendations For Microsoft PowerPoint Viewer 2003, consider avoiding the use of specially crafted PowerPoint files until a fix is available. As a temporary workaround, restrict access to potentially malicious files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0120

Affected Products

Powerpoint Viewer 2003
Office Powerpoint