Microsoft PowerPoint powerpnt.exe unspecified vulnerability

powerpoint-powerpnt-unspecified (27783) The risk level is classified as MediumMedium Risk

Description:

An unspecified vulnerability regarding the powerpnt.exe file in Microsoft PowerPoint has an unknown impact. It may be possible for a remote attacker to exploit this vulnerability to execute code or cause a denial of service by persuading a victim to open a malicious PowerPoint presentation (.ppt) either by sending the malicious file to a victim as an email attachment or hosting it on a Web site.

Platforms Affected:

  • Microsoft, PowerPoint 2003

Remedy:

No remedy available as of July 4, 2009.

Consequences:

Gain Access

References:

  • BugTraq Mailing List, Sat Jul 15 2006 - 03:15:08 CDT, MS Power Point Multiple Vulnerabilities (powerpnt.exe)- POC at http://archives.neohapsis.com/archives/bugtraq/2006-07/0207.html.
  • BID-18993: Microsoft Powerpoint Multiple Unspecified Vulnerabilities
  • CVE-2006-3660: Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
  • SA21061: Microsoft PowerPoint Memory Corruption Vulnerability
  • VUPEN/ADV-2006-2815: Microsoft PowerPoint Presentation Handling Multiple Memory Corruption and DoS Vulnerabilities

Reported:

Jul 15, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page