Lucene search

K
saintSAINT CorporationSAINT:960FD30FB661788E28E28083E5DE6618
HistoryApr 20, 2009 - 12:00 a.m.

Microsoft PowerPoint invalid object reference vulnerability

2009-04-2000:00:00
SAINT Corporation
my.saintcorporation.com
22

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.932

Percentile

99.1%

Added: 04/20/2009
CVE: CVE-2009-0556
BID: 34351
OSVDB: 53182

Background

Microsoft PowerPoint is presentation software included in the Microsoft Office desktop suite.

Problem

A memory corruption vulnerability in Microsoft PowerPoint allows command execution when an invalid object is referenced.

Resolution

Use one of the workarounds described in Microsoft security advisory 969136.

References

<http://www.kb.cert.org/vuls/id/627331&gt;

Limitations

Exploit works on Microsoft PowerPoint 2003 SP3 and requires a user to open the exploit file in Microsoft PowerPoint.

Platforms

Windows XP

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.932

Percentile

99.1%