PT-2008-1775 · Microsoft · Powerpoint Viewer 2003+1
Ruben Santamarta
·
Published
2008-08-12
·
Updated
2018-10-12
·
CVE-2008-0120
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft PowerPoint Viewer 2003
Description
The issue allows remote attackers to execute arbitrary code via a specially crafted PowerPoint file, potentially leading to memory corruption. This can be exploited by creating a malicious PowerPoint file that could be sent as an email attachment or hosted on a compromised website. If successfully exploited, an attacker could gain complete control of the affected system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights. The impact may be less severe for users with limited user rights.
Recommendations
For Microsoft PowerPoint Viewer 2003, consider avoiding the use of specially crafted PowerPoint files until a fix is available. As a temporary workaround, restrict access to potentially malicious files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powerpoint Viewer 2003
Office Powerpoint