Microsoft PowerPoint List Value Parsing Remote Code Execution Vulnerability
BID:30579
Info
Microsoft PowerPoint List Value Parsing Remote Code Execution Vulnerability
| Bugtraq ID: | 30579 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1455 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2008 12:00AM |
| Updated: | Aug 21 2008 01:25AM |
| Credit: | ADLab of Venustech |
| Vulnerable: |
Microsoft PowerPoint 2007 SP1 Microsoft PowerPoint 2007 0 Microsoft PowerPoint 2003 SP3 Microsoft PowerPoint 2003 SP2 Microsoft PowerPoint 2002 SP3 Microsoft PowerPoint 2000 SP3 Microsoft Office Compatibility Pack 2007 SP1 Microsoft Office Compatibility Pack 2007 0 Microsoft Office 2004 for Mac 0 |
| Not Vulnerable: | |
Discussion
Microsoft PowerPoint List Value Parsing Remote Code Execution Vulnerability
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious PowerPoint file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious PowerPoint file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Exploit / POC
Microsoft PowerPoint List Value Parsing Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft PowerPoint List Value Parsing Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
2008/08/20: Microsft has released version 2 of their fixes for this issue. Users who manually installed version 1 of the fixes may need to reinstall version 2. Please see the updated Microsoft advisory for more information.
Microsoft PowerPoint 2002 SP3
Microsoft PowerPoint 2007 SP1
Microsoft Office 2004 for Mac 0
Microsoft PowerPoint 2007 0
Microsoft PowerPoint 2000 SP3
Microsoft Office Compatibility Pack 2007 0
Microsoft PowerPoint 2003 SP3
Microsoft PowerPoint 2003 SP2
Microsoft Office Compatibility Pack 2007 SP1
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
2008/08/20: Microsft has released version 2 of their fixes for this issue. Users who manually installed version 1 of the fixes may need to reinstall version 2. Please see the updated Microsoft advisory for more information.
Microsoft PowerPoint 2002 SP3
-
Microsoft Security Update for Microsoft PowerPoint 2002 (KB948995)
http://www.microsoft.com/downloads/details.aspx?FamilyId=f8921074-7985 -4d42-ac2b-d2f3b1d466ba&displaylang=en
Microsoft PowerPoint 2007 SP1
-
Microsoft Security Update for Microsoft Office PowerPoint 2007 (KB951338)
http://www.microsoft.com/downloads/details.aspx?FamilyId=55fd618a-e9c5 -4f1e-b9a5-b2e47ec98ef1&displaylang=en
Microsoft Office 2004 for Mac 0
-
Microsoft Microsoft Office 2004 for Mac 11.5.1 Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=EBD3AF0C-3F62 -4D18-BF45-881655683BD5&displaylang=en
Microsoft PowerPoint 2007 0
-
Microsoft Security Update for Microsoft Office PowerPoint 2007 (KB951338)
http://www.microsoft.com/downloads/details.aspx?FamilyId=55fd618a-e9c5 -4f1e-b9a5-b2e47ec98ef1&displaylang=en
Microsoft PowerPoint 2000 SP3
-
Microsoft Security Update for Microsoft Power Point 2000 (KB949007)
http://www.microsoft.com/downloads/details.aspx?FamilyId=e7c044d8-778a -4985-b25b-4f7f6e4abadd&displaylang=en
Microsoft Office Compatibility Pack 2007 0
-
Microsoft Security Update for Microsoft Office System 2007 (KB954038)
http://www.microsoft.com/downloads/details.aspx?familyid=84ce5d58-0010 -4945-bce9-67a41f898f2f&displaylang=en
Microsoft PowerPoint 2003 SP3
-
Microsoft Security Update for Microsoft Office PowerPoint 2003 (KB948988)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7a7c21f0-5e0e -4dee-9710-1ce3d565913f&displaylang=en
Microsoft PowerPoint 2003 SP2
-
Microsoft Security Update for Microsoft Office PowerPoint 2003 (KB948988)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7a7c21f0-5e0e -4dee-9710-1ce3d565913f&displaylang=en
Microsoft Office Compatibility Pack 2007 SP1
-
Microsoft Security Update for Microsoft Office System 2007 (KB954038)
http://www.microsoft.com/downloads/details.aspx?familyid=84ce5d58-0010 -4945-bce9-67a41f898f2f&displaylang=en
References
Microsoft PowerPoint List Value Parsing Remote Code Execution Vulnerability
References:
References:
- Microsoft PowerPoint Homepage (Microsoft)
- Microsoft Security Bulletin MS08-051 (Microsoft)