Microsoft Powerpoint Remote Code Execution Vulnerability
BID:18957
CVE-2006-3590 |Info
Microsoft Powerpoint Remote Code Execution Vulnerability
| Bugtraq ID: | 18957 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3590 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2006 12:00AM |
| Updated: | Aug 08 2006 08:20PM |
| Credit: | The original discoverer of this issue is currently not known. |
| Vulnerable: |
Microsoft PowerPoint v. X for Mac 0 Microsoft PowerPoint 2004 for Mac 0 Microsoft PowerPoint 2003 SP3 Microsoft PowerPoint 2003 SP2 Microsoft PowerPoint 2003 SP1 Microsoft PowerPoint 2003 0 Microsoft PowerPoint 2002 SP3 Microsoft PowerPoint 2002 SP2 Microsoft PowerPoint 2002 SP1 Microsoft PowerPoint 2002 Microsoft PowerPoint 2000 SP3 Microsoft PowerPoint 2000 SR1 Microsoft PowerPoint 2000 SP2 Microsoft PowerPoint 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Powerpoint Remote Code Execution Vulnerability
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of targeted users.
A malicious code named 'Trojan.PPDropper.B' is actively exploiting this vulnerability.
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of targeted users.
A malicious code named 'Trojan.PPDropper.B' is actively exploiting this vulnerability.
Exploit / POC
Microsoft Powerpoint Remote Code Execution Vulnerability
This issue is actively being exploited in the wild by 'Trojan.PPDropper.B'.
This issue is actively being exploited in the wild by 'Trojan.PPDropper.B'.
Solution / Fix
Microsoft Powerpoint Remote Code Execution Vulnerability
Solution:
Microsoft has released a security bulletin to address this issue. Please see the attached security bulletin for further information.
Microsoft PowerPoint 2003 0
Microsoft PowerPoint 2002
Microsoft PowerPoint 2004 for Mac 0
Microsoft PowerPoint 2000
Solution:
Microsoft has released a security bulletin to address this issue. Please see the attached security bulletin for further information.
Microsoft PowerPoint 2003 0
-
Microsoft Security Update for Office 2003 (KB921566)
http://www.microsoft.com/downloads/details.aspx?familyid=DE1CB2A7-5D4C -44B8-BC40-7E0A88CC3081&displaylang=en
Microsoft PowerPoint 2002
-
Microsoft Security Update for Office XP (KB921567)
http://www.microsoft.com/downloads/details.aspx?familyid=A9C7E43B-A0A6 -4C81-87ED-3F4DED78EAEA&displaylang=en
Microsoft PowerPoint 2004 for Mac 0
-
Microsoft Microsoft Office 2004 for Mac 11.2.6 Update
http://download.microsoft.com/download/1/2/4/12449c3e-3871-4534-b4c9-a 4a56900c5fd/Office2004-1126UpdateEN.dmg -
Microsoft Microsoft Office v. X for Mac Security Update
http://download.microsoft.com/download/E/6/7/E67E3229-CA3F-40A4-9583-5 F0870200FE9/OfficeX-SecUpdate0608EN.dmg
Microsoft PowerPoint 2000
-
Microsoft Security Update for Office 2000 (KB921568)
http://www.microsoft.com/downloads/details.aspx?familyid=B7B5615B-7C20 -4C49-892F-7F4CCC2D6006&displaylang=en
References
Microsoft Powerpoint Remote Code Execution Vulnerability
References:
References:
- Information on the recent Powerpoint vulnerability. (Microsoft)
- Microsoft PowerPoint Home Page (Microsoft)
- Microsoft Security Advisory (922970) (Microsoft)
- Microsoft Security Bulletin MS06-048 (Microsoft)
- Microsoft Technet Security (Microsoft)
- Trojan.PPDropper.B (Symantec)
- Vulnerability Note VU#936945 - Microsoft PowerPoint contains an unspecified remo (US-CERT)