Microsoft Windows Knowledge Base Article 975416 update is not installed (WinMs10kb975416Update)

Vuln ID: 55890
Risk Level: High risk vulnerability  High WinMs10kb975416Update
Platforms: Microsoft PowerPoint: 2002 SP3, Microsoft PowerPoint: 2003 SP3, Microsoft Office: 2004 Mac OS
Description:

Microsoft Knowledge Base Article 975416 is not installed, which could allow a remote attacker to exploit the following vulnerabilities:

Microsoft PowerPoint is vulnerable to a buffer overflow, caused by improper bounds checking when handling a PowerPoint file path. By persuading a victim to open a specially-crafted PowerPoint file, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the application to crash.

Microsoft PowerPoint is vulnerable to a heap-based buffer overflow, caused by improper bounds checking when handling a LinkedSlideAtom. By persuading a victim to open a specially-crafted PowerPoint file, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the application to crash.

Microsoft PowerPoint could allow a remote attacker to execute arbitrary code on the system, caused by invalid array indexing error when handling the OEPlaceholderAtom placementId . By persuading a victim to open a malicious PowerPoint file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.

Microsoft PowerPoint could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error when handling OEPlaceholderAtom . By persuading a victim to open a malicious PowerPoint file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.

Microsoft PowerPoint Viewer is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when handling TextBytesAtom. By persuading a victim to open a specially-crafted PowerPoint file, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the application to crash.

Microsoft PowerPoint Viewer is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when handling TextCharsAtom. By persuading a victim to open a specially-crafted PowerPoint file, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the application to crash.

Remedy:

Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS10-004. See References.

False Positives:
False Negatives:
Required Permission: Windows login
Additional Information:

References:

Microsoft Security Bulletin MS10-004
Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (975416)
http://www.microsoft.com/technet/security/bulletin/ms10-004.mspx

IBM Internet Security Systems X-Force Database
Microsoft PowerPoint file path buffer overflow
http://xforce.iss.net/xforce/xfdb/55884

IBM Internet Security Systems X-Force Database
Microsoft PowerPoint LinkedSlideAtom buffer overflow
http://xforce.iss.net/xforce/xfdb/55885

IBM Internet Security Systems X-Force Database
Microsoft PowerPoint placementId code execution
http://xforce.iss.net/xforce/xfdb/55886

IBM Internet Security Systems X-Force Database
Microsoft PowerPoint OEPlaceholderAtom code execution
http://xforce.iss.net/xforce/xfdb/55887

IBM Internet Security Systems X-Force Database
Microsoft PowerPoint Viewer TextBytesAtom buffer overflow
http://xforce.iss.net/xforce/xfdb/55888

IBM Internet Security Systems X-Force Database
Microsoft PowerPoint ViewerTextCharsAtom buffer overflow
http://xforce.iss.net/xforce/xfdb/55889

ISS X-Force
Microsoft Windows Knowledge Base Article 975416 update is not installed
http://www.iss.net/security_center/static/55890.php

CVE CVE-2010-0034
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0034

CVE CVE-2010-0033
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0033

CVE CVE-2010-0029
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0029

CVE CVE-2010-0030
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0030

CVE CVE-2010-0031
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0031

CVE CVE-2010-0032
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0032


X-Force Logo
Know Your Risks
Mitre.org CVE Logo
Common Vulnerabilties & Exposures