Microsoft PowerPoint Record Improper Memory Access Remote Code Execution Vulnerability
BID:20325
Info
Microsoft PowerPoint Record Improper Memory Access Remote Code Execution Vulnerability
| Bugtraq ID: | 20325 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-3877 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2006 12:00AM |
| Updated: | Feb 20 2007 08:27PM |
| Credit: | Chris Ries is credited with the discovery of this vulnerability. |
| Vulnerable: |
Nortel Networks Contact Center - CCT 0 Microsoft Visio 2002 Standard SP2 Microsoft Visio 2002 Professional SP2 Microsoft Visio 2002 SP2 Microsoft Project 2002 SP1 Microsoft Project 2000 SR1 Microsoft PowerPoint 2003 SP3 Microsoft PowerPoint 2003 SP2 Microsoft PowerPoint 2003 SP1 Microsoft PowerPoint 2003 0 Microsoft PowerPoint 2003 0 Microsoft PowerPoint 2002 SP3 Microsoft PowerPoint 2002 SP2 Microsoft PowerPoint 2002 SP1 Microsoft PowerPoint 2002 Microsoft PowerPoint 2000 SP3 Microsoft PowerPoint 2000 SR1 Microsoft PowerPoint 2000 SP2 Microsoft PowerPoint 2000 Microsoft Office XP Developer Edition Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office X for Mac 0 Microsoft Office v. X Microsoft Office 2004 for Mac 0 Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 |
| Not Vulnerable: |
Microsoft PowerPoint Viewer 2003 0 Microsoft Office 2007 0 |
Discussion
Microsoft PowerPoint Record Improper Memory Access Remote Code Execution Vulnerability
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
Exploiting this issue can allow remote attackers to execute arbitrary code on a vulnerable computer by supplying a malicious PowerPoint (.ppt) document to a user.
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
Exploiting this issue can allow remote attackers to execute arbitrary code on a vulnerable computer by supplying a malicious PowerPoint (.ppt) document to a user.
Exploit / POC
Microsoft PowerPoint Record Improper Memory Access Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Microsoft PowerPoint Record Improper Memory Access Remote Code Execution Vulnerability
Solution:
The vendor has released advisory MS06-058 to address this issue in supported versions of affected applications.
The vendor has released advisory MS07-015 to address this issue because the previous update did not properly correct the vulnerability.
Microsoft Visio 2002 Professional SP2
Microsoft Project 2000 SR1
Microsoft Project 2002 SP1
Microsoft Office XP SP3
Microsoft Office 2003 SP2
Microsoft Office 2000 SP3
Microsoft Visio 2002 SP2
Microsoft Visio 2002 Standard SP2
Solution:
The vendor has released advisory MS06-058 to address this issue in supported versions of affected applications.
The vendor has released advisory MS07-015 to address this issue because the previous update did not properly correct the vulnerability.
Microsoft Visio 2002 Professional SP2
-
Microsoft Security Update for Visio 2002 (KB929063)
http://www.microsoft.com/downloads/details.aspx?familyid=F50A5111-0926 -4221-96DF-18294230ED1E&displaylang=en
Microsoft Project 2000 SR1
-
Microsoft Security Update for Project 2000 (KB929062)
http://www.microsoft.com/downloads/details.aspx?familyid=3DF54B5C-CB82 -4A99-9B90-EDAB38AD6310&displaylang=en
Microsoft Project 2002 SP1
-
Microsoft Security Update for Project 2002 (KB929063)
http://www.microsoft.com/downloads/details.aspx?familyid=419191DC-01B8 -4E2A-BA5B-71BF3066C169&displaylang=en
Microsoft Office XP SP3
-
Microsoft Security Update for Office XP (KB929063)
http://www.microsoft.com/downloads/details.aspx?familyid=C54B1FDA-1237 -48F7-AD19-F0830EE0E8FF&displaylang=en
Microsoft Office 2003 SP2
-
Microsoft Security Update for Office 2003 (KB929064)
http://www.microsoft.com/downloads/details.aspx?familyid=BB0973E7-275D -4491-9BA1-91EAEA84EEFD&displaylang=en
Microsoft Office 2000 SP3
-
Microsoft Security Update for Office 2000 (KB929062)
http://www.microsoft.com/downloads/details.aspx?familyid=20E089E7-7DD3 -44A4-ABFE-6D8C27721683&displaylang=en
Microsoft Visio 2002 SP2
-
Microsoft Security Update for Visio 2002 (KB929063)
http://www.microsoft.com/downloads/details.aspx?familyid=F50A5111-0926 -4221-96DF-18294230ED1E&displaylang=en
Microsoft Visio 2002 Standard SP2
-
Microsoft Security Update for Visio 2002 (KB929063)
http://www.microsoft.com/downloads/details.aspx?familyid=F50A5111-0926 -4221-96DF-18294230ED1E&displaylang=en
References
Microsoft PowerPoint Record Improper Memory Access Remote Code Execution Vulnerability
References:
References:
- 2007007745 - NORTEL RESPONSE TO MICROSOFT SECURITY BULLETIN MS07-015 (Nortel Networks)
- Microsoft Office Product Homepage (Microsoft)
- Microsoft Security Bulletin MS06-058 - Microsoft Security Bulletin MS06-058 (Microsoft)
- MS07-015 - Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (Microsoft)