Lucene search

K
saintSAINT CorporationSAINT:7632C7E6D0764BDD359E79601516EA53
HistoryMay 21, 2009 - 12:00 a.m.

Microsoft PowerPoint 2000 CurrentUserAtom buffer overflow

2009-05-2100:00:00
SAINT Corporation
my.saintcorporation.com
23

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.882

Percentile

98.8%

Added: 05/21/2009
CVE: CVE-2009-1131
BID: 34841
OSVDB: 54393

Background

Microsoft PowerPoint is presentation software included in the Microsoft Office desktop suite.

Problem

A buffer overflow vulnerability in Microsoft PowerPoint allows command execution when a user opens a presentation containing a specially crafted CurrentUserAtom record.

Resolution

Apply the update referenced in Microsoft Security Bulletin 09-017.

References

<http://www.microsoft.com/technet/security/bulletin/MS09-017.mspx&gt;

Limitations

Exploit works on Microsoft PowerPoint 2000 SP3.

Platforms

Windows XP

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.882

Percentile

98.8%