| Microsoft Windows Knowledge Base Article 975416 update is not installed (WinMs10kb975416Update) |
|---|
| Vuln ID: | 55890 | |
|---|---|---|
| Risk Level: | High |
WinMs10kb975416Update |
| Platforms: | Microsoft PowerPoint: 2002 SP3, Microsoft PowerPoint: 2003 SP3, Microsoft Office: 2004 Mac OS | |
| Description: | Microsoft Knowledge Base Article 975416 is not installed, which could allow a remote attacker to exploit the following vulnerabilities: Microsoft PowerPoint is vulnerable to a buffer overflow, caused by improper bounds checking when handling a PowerPoint file path. By persuading a victim to open a specially-crafted PowerPoint file, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the application to crash. Microsoft PowerPoint is vulnerable to a heap-based buffer overflow, caused by improper bounds checking when handling a LinkedSlideAtom. By persuading a victim to open a specially-crafted PowerPoint file, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the application to crash. Microsoft PowerPoint could allow a remote attacker to execute arbitrary code on the system, caused by invalid array indexing error when handling the OEPlaceholderAtom placementId . By persuading a victim to open a malicious PowerPoint file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. Microsoft PowerPoint could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error when handling OEPlaceholderAtom . By persuading a victim to open a malicious PowerPoint file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. Microsoft PowerPoint Viewer is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when handling TextBytesAtom. By persuading a victim to open a specially-crafted PowerPoint file, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the application to crash. Microsoft PowerPoint Viewer is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when handling TextCharsAtom. By persuading a victim to open a specially-crafted PowerPoint file, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the application to crash. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS10-004. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Microsoft Security Bulletin MS10-004 IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database ISS X-Force CVE CVE-2010-0034 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |