CVE-2009-0556

Description

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka Memory Corruption Vulnerability.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
78.206

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft PowerPoint 2000 (KB957790)Windows
Security Update for Microsoft PowerPoint 2003 (KB957784)Windows
Security Update for Microsoft PowerPoint 2007 (KB957789)Windows
Security Update for PowerPoint Viewer 2003 (KB969615)Windows
Security Update for the 2007 Microsoft Office System (KB969618)Windows
Security Update for PowerPoint Viewer 2007 (KB970059)Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234