Lucene search

K
cve[email protected]CVE-2006-3590
HistoryJul 14, 2006 - 6:05 p.m.

CVE-2006-3590

2006-07-1418:05:00
web.nvd.nist.gov
25
cve-2006-3590
mso.dll
microsoft powerpoint
memory corruption
user-assisted
trojan.ppdropper.b

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.455 Medium

EPSS

Percentile

97.4%

mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.

Affected configurations

NVD
Node
microsoftpowerpointMatch2000
OR
microsoftpowerpointMatch2002
OR
microsoftpowerpointMatch2003
OR
microsoftpowerpointMatch2003sp1
OR
microsoftpowerpointMatch2003sp2

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.455 Medium

EPSS

Percentile

97.4%