BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to the Zeroday Tracker: Your Vulnerability Watchlist

Get critical updates on the latest zeroday threats, including impact, mitigation and protection information - only from BeyondTrust.

PowerPoint Controlppt

Disclosed September 27, 2006    Fully Patched

Vulnerability Description:

A remote code execution vulnerability exists within Microsoft PowerPoint which may allow for a remote attacker to execute arbitrary code under the context of the logged in user. This vulnerability requires user interaction. In a web-based scenario (e-mail, Web site), a user would still have to open a file manually, as it would not be auto-opened.

Vendors:

Microsoft

Vulnerable Software/Devices:

PowerPoint 2000
PowerPoint XP
PowerPoint 2003
Office 2004 for Mac
Office v.X for Mac

Vulnerability Severity:

High

Exploit Availability:

N/A

BeyondTrust Prevention and Detection:

BeyondTrust's Blink® Personal Edition protects from this vulnerability.
BeyondTrust's Blink® Professional Edition protects from this vulnerability.
BeyondTrust's Retina® Network Security Scanner scans devices to detect for this vulnerability.

Patch:
Microsoft Patch - MS06-058

Mitigation:

There is no mitigation for this vulnerability other than applying MS06-058.

Links:

CVE-2006-4694

CVE(s):

None

Leave a Reply