Retired: Microsoft PowerPoint Remote Code Execution Vulnerability
BID:20059
CVE-2006-4854 |Info
Retired: Microsoft PowerPoint Remote Code Execution Vulnerability
| Bugtraq ID: | 20059 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4854 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2006 12:00AM |
| Updated: | Sep 21 2006 12:41AM |
| Credit: | Symantec has received samples of malicious content exploiting this issue. The original discoverer of this issue is currently unknown. |
| Vulnerable: |
Microsoft PowerPoint 2000 Chinese Edition Microsoft Office 2000 Chinese Version |
| Not Vulnerable: | |
Discussion
Retired: Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
This issue can allow remote attackers to execute arbitrary code on a vulnerable computer by supplying a malicious PowerPoint document to a user. This issue is being actively exploited in the wild as Trojan.PPDropper.E.
This issue is a duplicate of that discussed in BID 17000 (Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability) and is therefore being retired.
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
This issue can allow remote attackers to execute arbitrary code on a vulnerable computer by supplying a malicious PowerPoint document to a user. This issue is being actively exploited in the wild as Trojan.PPDropper.E.
This issue is a duplicate of that discussed in BID 17000 (Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability) and is therefore being retired.
Exploit / POC
Retired: Microsoft PowerPoint Remote Code Execution Vulnerability
An exploit is known to be circulating in the wild.
An exploit is known to be circulating in the wild.
Solution / Fix
Retired: Microsoft PowerPoint Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
This issue is a duplicate of that discussed in BID 17000 (Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability) and is therefore being retired.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
This issue is a duplicate of that discussed in BID 17000 (Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability) and is therefore being retired.
References
Retired: Microsoft PowerPoint Remote Code Execution Vulnerability
References:
References:
- Microsoft Office Product Homepage (Microsoft)
- Microsoft PowerPoint 0-day Vulnerability FAQ - September 2006, CVE-2006-4854 (Juha-Matti)
- Technet Security (Microsoft)
- Trojan.PPDropper.E (Symantec)
- New PowerPoint 0-day Trojan in the wild (Juha-Matti Laurio)