Privacy and Legal Notice

CIAC INFORMATION BULLETIN

R-008: Vulnerabilities in Microsoft PowerPoint

[Microsoft Security Bulletin MS06-058 (924163)]

October 10, 2006 18:00 GMT
[REVISED 19 Oct 2006]
[REVISED 23 Feb 2007]
[REVISED 28 Feb 2007]

PROBLEM: A remote code execution vulnerability exists in PowerPoint.
PLATFORM: Tested Software and Security Update Download Locations:
Affected Software:
• Microsoft Office 2000 Service Pack 3
• Microsoft PowerPoint 2000
• Microsoft Office XP Service Pack 3
• Microsoft PowerPoint 2002
• Microsoft Office 2003 Service Pack 1 or Service Pack 2
• Microsoft Office PowerPoint 2003
• Microsoft Office 2004 for Mac
• Microsoft PowerPoint 2004 for Mac
• Microsoft Office v. X for Mac
• Microsoft PowerPoint v. X for Mac
Non-Affected Software:
• Microsoft PowerPoint 2003 Viewer
Storage Management Appliance v2.1 Software running on:
   I, II, III
DAMAGE: An attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/r-008.shtml
  ORIGINAL BULLETIN: Microsoft Security Bulletin MS06-058 (924163)
   http://www.microsoft.com/technet/security/Bulletin/MS06-058.mspx
  ADDITIONAL LINK: Visit Hewlett-Packard's Subscription Service for:
   HPSBST02161 SSRT061264 rev. 1
   HPSBST02194 SSRT071306 rev. 1
  CVE: CVE-2006-3435 CVE-2006-3876 CVE-2006-3877 CVE-2006-4694

REVISION HISTORY:
10/19/2006 - revised to add a link to Hewlett-Packard HSPBST02161 SSRT061264 
             rev. 1 for Storage Management Appliance v2.1 Software running on 
			 I, II, III.
02/23/2007 - revised R-008 to reflect changes Microsoft has made in MS06-058 
             where updated further investigation of CVE-2006-3877 , MS07-015 
			 has been issued to properly address CVE-2006-3877.
02/27/2007 - revised R-008 to add a link to Hewlett-Packard HPSBST02194 SSRT071306
             rev. 1 for Storage Management Appliance I, II, III.



[***** Start Microsoft Security Bulletin MS06-058 (924163) *****]


Microsoft Security Bulletin MS06-058

Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (924163)

Published: October 10, 2006 | Updated: February 21, 2007

Version: 1.1

Summary

Who Should Read this Document: Customers who use Microsoft PowerPoint

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: This bulletin replaces a prior security update. See the frequently asked questions (FAQ) section of this bulletin for the complete list.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Office 2000 Service Pack 3 — Download the update (KB923093)

Microsoft PowerPoint 2000

Microsoft Office XP Service Pack 3 — Download the update (KB923092)

Microsoft PowerPoint 2002

Microsoft Office 2003 Service Pack 1 or Service Pack 2 — Download the update (KB923091)

Microsoft Office PowerPoint 2003

Microsoft Office 2004 for Mac

Microsoft PowerPoint 2004 for Mac - Download the update (KB924999)

Microsoft Office v. X for Mac

Microsoft PowerPoint v. X for Mac - Download the update (KB924998)

Non-Affected Software:

Microsoft PowerPoint 2003 Viewer

The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.

Top of sectionTop of section

General Information

Executive Summary

Executive Summary:

This update addresses several newly discovered, privately and publicly reported vulnerabilities. Each vulnerability is documented in this bulletin in its own "Vulnerability Details" section.

When using vulnerable versions of PowerPoint, if a user were logged on with administrative user rights, an attacker who successfully exploited these vulnerabilities could take complete control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

We recommend that customers apply the update immediately.

Severity Ratings and Vulnerability Identifiers:

Vulnerability Identifiers Impact of Vulnerability Microsoft PowerPoint 2000 Microsoft PowerPoint 2002 Microsoft Office PowerPoint 2003 Microsoft PowerPoint 2004 for Mac and PowerPoint v.X for Mac

PowerPoint Malformed Object Pointer Vulnerability - CVE-2006-3435

Remote Code Execution

None

None

Important

None

PowerPoint Malformed Data Record Vulnerability - CVE-2006-3876

Remote Code Execution

Critical

Important

Important

Important

PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877

Remote Code Execution

Critical

Important

Important

Important

PowerPoint Malformed Record Vulnerability - CVE-2006-4694

Remote Code Execution

Critical

Important

Important

Important

Aggregate Severity of All Vulnerabilities

 

Critical

Important

Important

Important

This assessment is based on the types of systems that are affected by the vulnerability, their typical deployment patterns, and the effect that exploiting the vulnerability would have on them.

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

PowerPoint Malformed Object Pointer Vulnerability - CVE-2006-3435:

A remote code execution vulnerability exists in PowerPoint. An attacker could exploit this vulnerability when PowerPoint parsed a file that included a malformed object pointer.

If a user were logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

Mitigating Factors for PowerPoint Malformed Object Pointer Vulnerability - CVE-2006-3435:
Workarounds for PowerPoint Malformed Object Pointer Vulnerability - CVE-2006-3435:
FAQ for PowerPoint Malformed Object Pointer Vulnerability - CVE-2006-3435:

PowerPoint Malformed Data Record Vulnerability - CVE-2006-3876:

A remote code execution vulnerability exists in PowerPoint. An attacker could exploit this vulnerability when PowerPoint parsed a file that included a malformed Data record.

If a user were logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

Mitigating Factors for PowerPoint Malformed Data Record Vulnerability -2006-3876:
Workarounds for PowerPoint Malformed Data Record Vulnerability - CVE-2006-3876:
FAQ for PowerPoint Malformed Data Record Vulnerability - CVE-2006-3876:

PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877:

A remote code execution vulnerability exists in PowerPoint and could be exploited when PowerPoint opened a specially crafted file. Such a file might be included in an e-mail attachment or hosted on a malicious web site. An attacker could exploit the vulnerability by constructing a specially crafted PowerPoint file that could allow remote code execution.

If a user were logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

Mitigating Factors for PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877:
Workarounds for PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877:
FAQ for PowerPoint Malformed Record Memory Corruption Vulnerability - CVE-2006-3877:

PowerPoint Malformed Record Vulnerability - CVE-2006-4694:

A remote code execution vulnerability exists in PowerPoint and could be exploited when PowerPoint opened a specially crafted file. Such a file might be included in an e-mail attachment or hosted on a malicious web site. An attacker could exploit the vulnerability by constructing a specially crafted PowerPoint file that could allow remote code execution.

If a user were logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

Mitigating Factors for PowerPoint Malformed Record Vulnerability - CVE-2006-4694:
Workarounds for PowerPoint Malformed Record Vulnerability - CVE-2006-4694:
FAQ for PowerPoint Malformed Record Vulnerability - CVE-2006-4694:

Security Update Information

Affected Software:

For information about the specific security update for your affected software, click the appropriate link:

PowerPoint 2000

PowerPoint 2002