Microsoft Office PowerPoint Multiple Vulnerabilities
RISK: Medium Risk
1. PowerPoint File Path Handling Buffer Overflow Vulnerability
A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
2. PowerPoint LinkedSlideAtom Heap Overflow Vulnerability
A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
3. PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability
A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
4. PowerPoint OEPlaceholderAtom Use After Free Vulnerability
A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
5. PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability
A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint viewer handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
6. Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability
A remote code execution vulnerability exists in the way that Microsoft Office PowerPoint Viewer handles specially crafted PowerPoint files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Office XP Service Pack 3
- Microsoft Office PowerPoint 2002 Service Pack 3 - Microsoft Office 2003 Service Pack 3
- Microsoft Office PowerPoint 2003 Service Pack 3 - Microsoft Office 2004 for Mac
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Download locations for this patch
- Microsoft Office XP Service Pack 3
- Microsoft Office PowerPoint 2002 Service Pack 3 - Microsoft Office 2003 Service Pack 3
- Microsoft Office PowerPoint 2003 Service Pack 3 - Microsoft Office 2004 for Mac
Vulnerability Identifier
Source
Related Link
Share with