PT-2010-1174 · Microsoft · Office Powerpoint

Alin Rad Pop

·

Published

2010-11-09

·

Updated

2025-03-26

·

CVE-2010-2572

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft PowerPoint versions 2002 SP3 through 2003 SP3
Description The issue is a buffer overflow in Microsoft PowerPoint, allowing remote attackers to execute arbitrary code via a crafted PowerPoint 95 document. This can give an attacker full control over the system, enabling them to install programs, view, modify, and delete data, as well as create new accounts with full user rights.
Recommendations For Microsoft PowerPoint versions 2002 SP3 and 2003 SP3, consider disabling the handling of PowerPoint 95 documents until a patch is available. As a temporary workaround, restrict access to the vulnerable component that handles PowerPoint 95 files to minimize the risk of exploitation. Avoid using the vulnerable version of Microsoft PowerPoint to open specially crafted PowerPoint 95 documents until the issue is resolved.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03588
CVE-2010-2572

Affected Products

Office Powerpoint