case Computer :

Microsoft PowerPoint Sound Data (CVE-2009-0227) Remote Code Execution Vulnerability

거곰 2009. 5. 13. 11:17
Bugtraq ID: 34882
Class: Boundary Condition Error
CVE: CVE-2009-0227
Remote: Yes
Local: No
Published: May 12 2009 12:00AM
Updated: May 12 2009 11:16PM
Credit: Marsu Pilami of VeriSign iDefense Labs


Discussion

Microsoft PowerPoint is prone to a remote code-execution vulnerability.

An attacker can exploit this issue by enticing a victim to open a specially crafted PowerPoint 4.0 file.

Successfully exploiting this issue can allow the attacker to execute arbitrary code in the context of the currently logged-in user.



Solution

The vendor has released an advisory and updates. Please see the references for details.

Microsoft PowerPoint 2002 SP3
Microsoft PowerPoint 2000 SP3
Microsoft PowerPoint 2003 SP3


 

References:





Vulnerable: Microsoft PowerPoint 2003 SP3
+ Microsoft Office 2003 SP3
+ Microsoft Office 2003 SP2
+ Microsoft Office 2003 SP1
+ Microsoft Office 2003 0
Microsoft PowerPoint 2002 SP3
Microsoft PowerPoint 2002 SP2
Microsoft PowerPoint 2002 SP1
2000 Terminal Services SP1
Microsoft PowerPoint 2002
+ Microsoft Office XP
Microsoft PowerPoint 2000 SP3
Microsoft PowerPoint 2000 SR1
Microsoft PowerPoint 2000 SP2
Microsoft PowerPoint 2000
+ Microsoft Office 2000

반응형