Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2010-02-09.3

iDefense Security Advisory 02.09.10 – Remote exploitation of an invalid array indexing vulnerability in Microsoft Corp.’s PowerPoint could allow an attacker to execute arbitrary code with the privileges of the current user. This vulnerability occurs when parsing an “OEPlaceholderAtom” record. This record type is used to create a placeholder for an object (picture, text, etc.) on a slide. By providing a value greater than the size of an array, it is possible to corrupt stack memory beyond the bounds of the array with a fixed value. By overwriting critical structures like the saved return address, it is possible to execute arbitrary code.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/86220/02.09.10-3.txt

Source: https://packetstormsecurity.com/files/86220/iDEFENSE-Security-Advisory-2010-02-09.3.html

Related posts
Advisories

CSIS2005-1.txt

Advisories

Secunia Security Advisory 17625

Advisories

Secunia Security Advisory 20411

Advisories

Secunia Security Advisory 23300