Lucene search

K
saintSAINT CorporationSAINT:3BED4A216C070A5D88F20D77327B1E29
HistoryMay 14, 2009 - 12:00 a.m.

Microsoft PowerPoint Legacy File Format Printer driver buffer overflow

2009-05-1400:00:00
SAINT Corporation
download.saintcorporation.com
9

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.919

Percentile

99.0%

Added: 05/14/2009
CVE: CVE-2009-0227
BID: 34882
OSVDB: 54384

Background

Microsoft PowerPoint is presentation software included in the Microsoft Office desktop suite.

Problem

A buffer overflow vulnerability in the Legacy File Format conversion filter (**PP4X322.dll**) allows command execution when a user opens a PowerPoint 4.0 file containing a Printer record structure with a specially crafted driver string.

Resolution

Apply the update referenced in Microsoft Security Bulletin 09-017.

References

<http://www.microsoft.com/technet/security/bulletin/MS09-017.mspx&gt;

Limitations

Exploit works on Microsoft PowerPoint 2002 and requires a user to open the exploit file in Microsoft PowerPoint.

There may be a delay before the exploit succeeds after the user opens the exploit file.

Platforms

Windows XP

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.919

Percentile

99.0%