1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution

Report ID: SA201006550
Source: F-Secure
Date of Discovery: 10.11.2010
Criticality: Urgent
Affects:
Microsoft PowerPoint 2002
Microsoft PowerPoint 2003
Microsoft PowerPoint Viewer 2007

Compromise From: From remote
Compromise Type: Remote code execution
System access

Summary

Vulnerabilities in Microsoft PowerPoint may be exploited using a specially crafted PowerPoint file to permit remote code execution, potentially allowing an attacker to take complete control of the system.

Detailed Description

The vulnerabilities are related to the way PowerPoint versions 2002 and 2003 handles specially crafted PowerPoint files. PowerPoint 2007 is not affected by these vulnerabilities; they do however affect PowerPoint Viewer 2007, which is delivered together with PowerPoint 2007.

A specially crafted PowerPoint file is required to target and exploit either one of the vulnerabilities. This file may be delivered as an attachment to an e-mail message or hosted on a website, which the user must be directed to in some way. In either case, the user must actively click and open the malicious PowerPoint file in order to be affected.

If the exploit is successful, an attacker can gain the same rights as the logged-in user. Users with administrative accounts may be more affected than those with fewer user rights.

Original Reference

http://www.microsoft.com/technet/security/Bulletin/MS10-088.mspx

CVE Reference

CVE-2010-2572
CVE-2010-2573