int(4580)

Vulnerability Bulletins


Ejecución remota de código en Microsoft Office PowerPoint

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft Office PowerPoint 2000 Service Pack 3
Microsoft Office PowerPoint 2002 Service Pack 3
Microsoft Office PowerPoint 2003 Service Pack 3
Microsoft Office 2004 para Mac

Description

Se ha descubierto una vulnerabilidad en Microsoft Office PowerPoint.

Un atacante remoto podría ejecutar código arbitrario mediante un fichero PowerPoint especialmente diseñado.

Solution



Actualización de software

Microsoft (MS09-017)
Microsoft Office 2000 Service Pack 3 / patch office2000-KB957790-FullFile-ENU
Microsoft Office XP Service Pack 3 / patch officexp-KB957781-FullFile-ENU
Microsoft Office 2003 Service Pack 3 / patch office2003-KB957784-FullFile-ENU
2007 Microsoft Office System SP 1 y SP 2 / patch powerpoint2007-kb957789-fullfile-x86-glb
PowerPoint Viewer 2003 / patch office2003-kb969615-fullfile-x86-en-us
PowerPoint Viewer 2007 SP 1 y PowerPoint Viewer 2007 SP 2 / patch office2007-kb970059-fullfile-x86-glb
Microsoft Office Compatibility Pack para Word, Excel y PowerPoint 2007 File Formats SP 1 y SP 2 / patch office2007-kb969618-fullfile-x86-glb

Standar resources

Property Value
CVE CVE-2009-0556
BID

Other resources

Microsoft Security Advisory (969136)
http://www.microsoft.com/technet/security/advisory/969136.mspx

Microsoft Security Bulletin (MS09-017)
http://www.microsoft.com/technet/security/bulletin/ms09-017.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2009-04-03
1.1 Aviso actualizado por Microsoft (MS09-017) 2009-05-13