Microsoft PowerPoint Invalid 'PersistDirectoryEntry' Record Remote Code Execution Vulnerability
BID:47251
Info
Microsoft PowerPoint Invalid 'PersistDirectoryEntry' Record Remote Code Execution Vulnerability
| Bugtraq ID: | 47251 |
| Class: | Unknown |
| CVE: |
CVE-2011-0656 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2011 12:00AM |
| Updated: | Apr 12 2011 08:34PM |
| Credit: | An anonymous researcher working with TippingPoint's Zero Day Initiative. |
| Vulnerable: |
Microsoft PowerPoint Web App Web App Microsoft PowerPoint Viewer 2007 SP2 Microsoft PowerPoint Viewer 2007 SP1 Microsoft PowerPoint Viewer 2007 0 Microsoft PowerPoint 2010 0 Microsoft PowerPoint 2007 SP2 Microsoft PowerPoint 2007 SP1 Microsoft PowerPoint 2007 0 Microsoft PowerPoint 2003 SP3 Microsoft PowerPoint 2003 SP2 Microsoft PowerPoint 2003 SP1 Microsoft PowerPoint 2003 0 Microsoft PowerPoint 2002 SP3 Microsoft PowerPoint 2002 SP2 Microsoft PowerPoint 2002 SP1 Microsoft PowerPoint 2002 Microsoft Open XML File Format Converter for Mac 0 Microsoft Office Compatibility Pack 2007 SP2 Microsoft Office Compatibility Pack 2007 SP1 Microsoft Office Compatibility Pack 2007 0 Microsoft Office 2011 for Mac 0 Microsoft Office 2008 for Mac 0 Microsoft Office 2004 for Mac 0 |
| Not Vulnerable: | |
Discussion
Microsoft PowerPoint Invalid 'PersistDirectoryEntry' Record Remote Code Execution Vulnerability
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing a victim to open a malicious PowerPoint file.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will cause a denial-of-service condition.
Microsoft PowerPoint is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing a victim to open a malicious PowerPoint file.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will cause a denial-of-service condition.
Exploit / POC
Microsoft PowerPoint Invalid 'PersistDirectoryEntry' Record Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft PowerPoint Invalid 'PersistDirectoryEntry' Record Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft PowerPoint 2002 SP3
Microsoft Office 2008 for Mac 0
Microsoft Office Compatibility Pack 2007 SP2
Microsoft PowerPoint 2003 SP3
Microsoft PowerPoint 2007 SP2
Microsoft Office 2011 for Mac 0
Microsoft Open XML File Format Converter for Mac 0
Microsoft Office 2004 for Mac 0
Microsoft PowerPoint 2010 0
Microsoft PowerPoint Viewer 2007 SP2
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft PowerPoint 2002 SP3
-
Microsoft officexp-KB2464617-FullFile-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=0d215ab6-c9be -4f43-9501-658bb7ef008e
Microsoft Office 2008 for Mac 0
-
Microsoft Office2008-1229UpdateEN.dmg
http://www.microsoft.com/downloads/details.aspx?FamilyID=84dfe3f4-a2a1 -47b9-8da1-29ae67230918
Microsoft Office Compatibility Pack 2007 SP2
-
Microsoft Office2007-kb2464635-fullfile-x86-glb.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=913efc28-7deb -47b8-8c22-8eb5fc2631e4
Microsoft PowerPoint 2003 SP3
-
Microsoft office2003-KB2464588-FullFile-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=2ce8349f-79b1 -41ef-a1c0-cbe40ccf9f20
Microsoft PowerPoint 2007 SP2
-
Microsoft PowerPoint2007-KB2464594-fullfile-x86-glb.exe
http://www.microsoft.com/downloads/details.aspx?familyid=6b2526fe-a061 -4a17-992e-ac867bef130e
Microsoft Office 2011 for Mac 0
-
Microsoft Office2011-1410UpdateEN.dmg
http://www.microsoft.com/downloads/details.aspx?FamilyID=ef1e612f-d8e3 -4628-9fe4-ad136f0debd3
Microsoft Open XML File Format Converter for Mac 0
-
Microsoft OpenXMLConverter119.dmg
http://www.microsoft.com/downloads/details.aspx?FamilyID=0c323a12-6385 -4666-ad39-a9516a8eda14
Microsoft Office 2004 for Mac 0
-
Microsoft Office2004-1163UpdateEN.dmg
http://www.microsoft.com/downloads/details.aspx?FamilyID=f756d836-6ab2 -4adb-9dee-6cb523d7c1f5
Microsoft PowerPoint 2010 0
-
Microsoft PowerPoint2010-kb2519975-fullfile-x86-glb.exe
http://www.microsoft.com/downloads/details.aspx?familyid=549ca7f0-44bf -4965-a9d2-aa5e8dac2238 -
Microsoft PowerPoint2010-kb2519975-fullfile-x64-glb.exe
http://www.microsoft.com/downloads/details.aspx?familyid=ef62deae-2b07 -41c9-a4bf-b746566e59ee
Microsoft PowerPoint Viewer 2007 SP2
-
Microsoft office2007-KB2464623-fullfile-x86-glb.exe
http://www.microsoft.com/downloads/details.aspx?FamilyID=6e23d3c3-2944 -42ea-80b3-0663af60d0f1
References
Microsoft PowerPoint Invalid 'PersistDirectoryEntry' Record Remote Code Execution Vulnerability
References:
References:
- Microsoft Office PowerPoint PersistDirectoryEntry Remote Code Execution Vulnerab (Zero Day Initiative)
- Microsoft PowerPoint Homepage (Microsoft)
- Microsoft Security Bulletin MS11-022 (Microsoft)