Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.902114
Categoría:Windows : Microsoft Bulletins
Título:Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (975416)
Resumen:This host is missing a critical security update according to; Microsoft Bulletin MS10-004.
Descripción:Summary:
This host is missing a critical security update according to
Microsoft Bulletin MS10-004.

Vulnerability Insight:
Multiple flaws are due to:

- Buffer overflow error when handling file paths.

- Heap overflow error when processing 'LinkedSlideAtom' records.

- Array indexing error when processing 'OEPlaceholderAtom' records with a
specially crafted 'placementId' field.

- Use-after-free error when processing 'OEPlaceholderAtom' records.

- Stack overflow error when processing 'TextBytesAtom' records.

- Stack overflow error when processing 'TextCharsAtom' records.

Vulnerability Impact:
Successful exploitation could allow attackers to execute arbitrary code by
tricking a user into opening a malicious PPT file.

Affected Software/OS:
- Microsoft Office PowerPoint 2002 SP 3 and prior

- Microsoft Office PowerPoint 2003 SP 3 and prior

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: BugTraq ID: 38099
BugTraq ID: 38101
BugTraq ID: 38103
BugTraq ID: 38104
BugTraq ID: 38107
BugTraq ID: 38108
Common Vulnerability Exposure (CVE) ID: CVE-2010-0029
Cert/CC Advisory: TA10-040A
http://www.us-cert.gov/cas/techalerts/TA10-040A.html
Microsoft Security Bulletin: MS10-004
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-004
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8410
http://www.securitytracker.com/id?1023563
Common Vulnerability Exposure (CVE) ID: CVE-2010-0030
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8050
Common Vulnerability Exposure (CVE) ID: CVE-2010-0031
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8081
Common Vulnerability Exposure (CVE) ID: CVE-2010-0032
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8303
Common Vulnerability Exposure (CVE) ID: CVE-2010-0033
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7711
Common Vulnerability Exposure (CVE) ID: CVE-2010-0034
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8268
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.