PT-2010-1174 · Microsoft · Office Powerpoint
Alin Rad Pop
·
Published
2010-11-09
·
Updated
2025-03-26
·
CVE-2010-2572
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft PowerPoint versions 2002 SP3 through 2003 SP3
Description
The issue is a buffer overflow in Microsoft PowerPoint, allowing remote attackers to execute arbitrary code via a crafted PowerPoint 95 document. This can give an attacker full control over the system, enabling them to install programs, view, modify, and delete data, as well as create new accounts with full user rights.
Recommendations
For Microsoft PowerPoint versions 2002 SP3 and 2003 SP3, consider disabling the handling of PowerPoint 95 documents until a patch is available.
As a temporary workaround, restrict access to the vulnerable component that handles PowerPoint 95 files to minimize the risk of exploitation.
Avoid using the vulnerable version of Microsoft PowerPoint to open specially crafted PowerPoint 95 documents until the issue is resolved.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Powerpoint