Skip to main content

Microsoft Office PowerPoint Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 10 Feb 2010 4253 Views

RISK: Medium Risk

1. PowerPoint File Path Handling Buffer Overflow Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

2. PowerPoint LinkedSlideAtom Heap Overflow Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

3. PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

4. PowerPoint OEPlaceholderAtom Use After Free Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

5. PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint viewer handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

6. Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability

A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint Viewer handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Office XP Service Pack 3
    - Microsoft Office PowerPoint 2002 Service Pack 3
  • Microsoft Office 2003 Service Pack 3
    - Microsoft Office PowerPoint 2003 Service Pack 3
  • Microsoft Office 2004 for Mac

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Download locations for this patch


Vulnerability Identifier


Source


Related Link