Vulnerability Name: | CVE-2006-0009 (CCN-25009) |
Assigned: | 2005-11-09 |
Published: | 2006-03-14 |
Updated: | 2018-10-19 |
Summary: | Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.
|
CVSS v3 Severity: | 8.6 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): High |
|
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 3.8 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C) 6.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Complete |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Gain Access |
References: | Source: FULLDISC Type: UNKNOWN 20060822 Major updates in PowerPoint FAQ document - not a 0-day issue
Source: MISC Type: UNKNOWN http://blogs.securiteam.com/?author=28
Source: MISC Type: UNKNOWN http://blogs.securiteam.com/?p=557
Source: MISC Type: UNKNOWN http://blogs.securiteam.com/?p=559
Source: MITRE Type: CNA CVE-2006-0009
Source: MISC Type: UNKNOWN http://isc.sans.org/diary.php?storyid=1618
Source: FULLDISC Type: UNKNOWN 20060919 New PowerPoint 0-day Trojan in the wild
Source: CCN Type: SA19138 Microsoft Office Multiple Code Execution Vulnerabilities
Source: SECUNIA Type: Patch, Vendor Advisory 19138
Source: CCN Type: SA19238 Avaya Modular Messaging Windows Privilege Escalation Security Issues
Source: SECUNIA Type: UNKNOWN 19238
Source: CCN Type: SECTRACK ID: 1015766 Microsoft Office and Excel Buffer Overflows Let Remote Users Execute Arbitrary Code
Source: SECTRACK Type: Patch 1015766
Source: CCN Type: SECTRACK ID: 1016720 [Duplicate Entry] Microsoft PowerPoint Unknown Bug May Let Remote Users Execute Arbitrary Code
Source: SECTRACK Type: UNKNOWN 1016720
Source: CCN Type: SECTRACK ID: 1016886 [Duplicate] Microsoft PowerPoint Bug Lets Remote Users Execute Arbitrary Code
Source: SECTRACK Type: UNKNOWN 1016886
Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm
Source: CCN Type: ASA-2006-069 Windows Security Updates for March 2006 - (MS06-011 MS06-012)
Source: CCN Type: Microsoft Security Bulletin MS11-096 Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241)
Source: CCN Type: Microsoft Security Bulletin MS12-028 Vulnerability in Microsoft Office Could Allow for Remote Code Execution (2639185)
Source: CCN Type: Microsoft Security Bulletin MS12-029 Vulnerability in Microsoft Word Could Allow Remote Code Execution (2680352)
Source: CCN Type: Microsoft Security Bulletin MS12-034 Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578)
Source: CCN Type: Microsoft Security Bulletin MS12-057 Vulnerability in Microsoft Office Could Allow for Remote Code Execution (2731879)
Source: CCN Type: Microsoft Security Bulletin MS12-064 Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2742319)
Source: CCN Type: Microsoft Security Bulletin MS12-065 Vulnerability in Microsoft Works Could Allow Remote Code Execution (KB2754670)
Source: CCN Type: Microsoft Security Bulletin MS12-070 Vulnerability in SQL Server Could Allow Elevation of Privilege (2754849)
Source: CCN Type: Microsoft Security Bulletin MS12-079 Vulnerability in Microsoft Word Could Allow Remote Code Execution (2780642)
Source: CCN Type: Microsoft Security Bulletin MS13-022 Vulnerability in Silverlight Could Allow Remote Code Execution (2814124)
Source: CCN Type: Microsoft Security Bulletin MS13-043 Vulnerability in Microsoft Word Could Allow Remote Code Execution (2830399)
Source: CCN Type: Microsoft Security Bulletin MS13-054 Vulnerability in Windows Components Could Allow Remote Code Execution (2848295)
Source: CCN Type: Microsoft Security Bulletin MS13-072 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2845537)
Source: CCN Type: Microsoft Security Bulletin MS13-085 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080)
Source: CCN Type: Microsoft Security Bulletin MS13-086 Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2885084)
Source: CCN Type: Microsoft Security Bulletin MS14-001 Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2916605)
Source: CCN Type: Microsoft Security Bulletin MS14-017 Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2949660)
Source: CCN Type: Microsoft Security Bulletin MS14-034 Vulnerability in Microsoft Word Could Allow Remote Code Execution (2969261)
Source: CCN Type: Microsoft Security Bulletin MS14-038 Vulnerability in Windows Journal Could Allow Remote Code Execution (2975689)
Source: CCN Type: Microsoft Security Bulletin MS14-044 Vulnerabilities in SQL Server Could Allow Elevation of Privilege (2984340)
Source: CCN Type: Microsoft Security Bulletin MS14-061 Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3000434)
Source: CCN Type: Microsoft Security Bulletin MS14-069 Vulnerability in Microsoft Office Could Allow Remote Code Execution (3009710)
Source: CCN Type: Microsoft Security Bulletin MS14-081 Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3017301)
Source: CCN Type: Microsoft Security Bulletin MS14-083 Vulnerabilities in MicrosoftExcel Could Allow Remote Code Execution (3017347)
Source: CCN Type: Microsoft Security Bulletin MS15-081 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3080790)
Source: CCN Type: Microsoft Security Bulletin MS15-099 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664)
Source: CCN Type: Microsoft Security Bulletin MS15-110 Security Updates for Microsoft Office (3096440)
Source: CCN Type: Microsoft Security Bulletin MS15-116 Security Updates for Microsoft Office to Address Remote Code Execution (3104540)
Source: CCN Type: Microsoft Security Bulletin MS15-131 Security Update for Microsoft Office to Address Remote Code Execution (3116111)
Source: CCN Type: Microsoft Security Bulletin MS16-004 Security Update for Microsoft Office to Address Remote Code Execution - Critical (3124585)
Source: CCN Type: Microsoft Security Bulletin MS16-015 Security Update for Microsoft Office to Address Remote Code Execution (3134226)
Source: CCN Type: Microsoft Security Bulletin MS16-029 Security Update for Microsoft Office to Address Remote Code Execution (3141806)
Source: CCN Type: Microsoft Security Bulletin MS16-042 Security Update for Microsoft Office (3148775)
Source: CCN Type: Microsoft Security Bulletin MS16-054 Security Update for Microsoft Office (3155544)
Source: CCN Type: Microsoft Security Bulletin MS16-070 Security Update for Office (3163610)
Source: CCN Type: Microsoft Security Bulletin MS16-088 Security Updates for Office (3170008)
Source: CCN Type: Microsoft Security Bulletin MS16-099 Security Update for Office (3177451)
Source: CCN Type: Microsoft Security Bulletin MS16-107 Security Update for Microsoft Office (3185852)
Source: CCN Type: Microsoft Security Bulletin MS16-121 Security Update for Microsoft Office (3194063)
Source: CCN Type: Microsoft Security Bulletin MS16-133 Security Update for Microsoft Office (3199168)
Source: CCN Type: Microsoft Security Bulletin MS16-148 Security Update for Microsoft Office (3204068)
Source: CCN Type: Microsoft Security Bulletin MS17-002 Security Update for Microsoft Office (3214291)
Source: CCN Type: Microsoft Security Bulletin MS17-013 Security Update for Microsoft Graphics Component (4013075)
Source: CCN Type: Microsoft Security Bulletin MS17-014 Security Update for Microsoft Office (4013241)
Source: MISC Type: UNKNOWN http://www.darkreading.com/document.asp?doc_id=101970
Source: CCN Type: US-CERT VU#682820 Microsoft Office routing slip buffer overflow
Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#682820
Source: CCN Type: Microsoft Security Bulletin MS06-012 Vulnerability in Microsoft Office May Lead to Remote Code Execution (905413)
Source: CCN Type: Microsoft Security Bulletin MS06-037 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (917285)
Source: CCN Type: Microsoft Security Bulletin MS06-059 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (924164)
Source: CCN Type: Microsoft Security Bulletin MS07-002 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (927198)
Source: CCN Type: Microsoft Security Bulletin MS07-023 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (934233)
Source: CCN Type: Microsoft Security Bulletin MS07-036 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (936542)
Source: CCN Type: Microsoft Security Bulletin MS07-044 Vulnerability in Microsoft Excel Could Allow Remote Code Execution (940965)
Source: CCN Type: Microsoft Security Bulletin MS08-014 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (949029)
Source: CCN Type: Microsoft Security Bulletin MS08-026 Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (951207)
Source: CCN Type: Microsoft Security Bulletin MS08-042 Vulnerability in Microsoft Word Could Allow Remote Code Execution (955048)
Source: CCN Type: Microsoft Security Bulletin MS08-043 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (954066)
Source: CCN Type: Microsoft Security Bulletin MS08-051 Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785)
Source: CCN Type: Microsoft Security Bulletin MS08-052 Vulnerabilities in GDI+ Could Allow Remote Code Execution (954593)
Source: CCN Type: Microsoft Security Bulletin MS08-057 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)
Source: CCN Type: Microsoft Security Bulletin MS09-004 Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420)
Source: CCN Type: Microsoft Security Bulletin MS09-017 Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (967340)
Source: CCN Type: Microsoft Security Bulletin MS09-021 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)
Source: CCN Type: Microsoft Security Bulletin MS09-062 Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)
Source: CCN Type: Microsoft Security Bulletin MS09-067 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)
Source: CCN Type: Microsoft Security Bulletin MS10-003 Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution (978214)
Source: CCN Type: Microsoft Security Bulletin MS10-004 Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (975416)
Source: CCN Type: Microsoft Security Bulletin MS10-017 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)
Source: CCN Type: Microsoft Security Bulletin MS10-028 Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (980094)
Source: CCN Type: Microsoft Security Bulletin MS10-036 Vulnerabilities in COM validation in Microsoft Office Could Allow Remote Code Execution (983235
Source: CCN Type: Microsoft Security Bulletin MS10-038 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452)
Source: CCN Type: Microsoft Security Bulletin MS10-056 Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638)
Source: CCN Type: Microsoft Security Bulletin MS10-057 Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707)
Source: CCN Type: Microsoft Security Bulletin MS10-079 Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194)
Source: CCN Type: Microsoft Security Bulletin MS10-087 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930)
Source: CCN Type: Microsoft Security Bulletin MS10-105 Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095)
Source: CCN Type: Microsoft Security Bulletin MS11-008 Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2451879)
Source: CCN Type: Microsoft Security Bulletin MS11-021 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2489279)
Source: CCN Type: Microsoft Security Bulletin MS11-023 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2489293)
Source: CCN Type: Microsoft Security Bulletin MS11-029 Vulnerability in GDI+ Could Allow Remote Code Execution (2489979)
Source: CCN Type: Microsoft Security Bulletin MS11-045 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2537146)
Source: CCN Type: Microsoft Security Bulletin MS11-049 Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893)
Source: CCN Type: Microsoft Security Bulletin MS11-060 Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2560978)
Source: CCN Type: Microsoft Security Bulletin MS11-072 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505)
Source: OSVDB Type: UNKNOWN 23903
Source: CCN Type: OSVDB ID: 23903 Microsoft Office Crafted Routing Slip Arbitrary Code Execution
Source: BUGTRAQ Type: UNKNOWN 20060314 SYMSA-2006-001: Buffer overflow in Microsoft Office 2000, Office XP (2002), and Office 2003 Routing Slip Metadata
Source: BUGTRAQ Type: UNKNOWN 20060422 PowerPoint Phishing Trojan
Source: BUGTRAQ Type: UNKNOWN 20060819 New PowerPoint 0-day and Trojan - FAQ document ready
Source: BUGTRAQ Type: UNKNOWN 20060822 Major updates in PowerPoint FAQ document - not a 0-day issue
Source: BUGTRAQ Type: UNKNOWN 20060919 New PowerPoint 0-day Trojan in the wild
Source: BUGTRAQ Type: UNKNOWN 20060919 Microsoft PowerPoint 0-day Vulnerability FAQ - September written
Source: BID Type: Patch 17000
Source: CCN Type: BID-17000 Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability
Source: BID Type: UNKNOWN 20059
Source: CCN Type: BID-20059 Retired: Microsoft PowerPoint Remote Code Execution Vulnerability
Source: CCN Type: Symantec Security Advisory SYMSA-2006-001 Buffer overflow in Microsoft Office 2000, Office XP (2002), and Office 2003 Routing Slip Metadata
Source: MISC Type: UNKNOWN http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt
Source: MISC Type: UNKNOWN http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99
Source: MISC Type: UNKNOWN http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH
Source: CERT Type: Third Party Advisory, US Government Resource TA06-073A
Source: VUPEN Type: UNKNOWN ADV-2006-0950
Source: VUPEN Type: UNKNOWN ADV-2006-3678
Source: MS Type: UNKNOWN MS06-012
Source: XF Type: UNKNOWN office-routing-slip-bo(25009)
Source: XF Type: UNKNOWN office-routing-slip-bo(25009)
Source: XF Type: UNKNOWN powerpoint-presentation-code-execution(29009)
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1504
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1553
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1653
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:798
|
Vulnerable Configuration: | Configuration 1: cpe:/a:microsoft:office:2000:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:office:2003:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:office:2003:sp2:*:*:*:*:*:*OR cpe:/a:microsoft:office:2004:*:mac:*:*:*:*:*OR cpe:/a:microsoft:office:v.x:*:mac:*:*:*:*:*OR cpe:/a:microsoft:office:xp:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:works:2000:*:*:*:*:*:*:*OR cpe:/a:microsoft:works:2001:*:*:*:*:*:*:*OR cpe:/a:microsoft:works:2002:*:*:*:*:*:*:*OR cpe:/a:microsoft:works:2003:*:*:*:*:*:*:*OR cpe:/a:microsoft:works:2004:*:*:*:*:*:*:*OR cpe:/a:microsoft:works:2005:*:*:*:*:*:*:*OR cpe:/a:microsoft:works:2006:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:microsoft:works:2004:*:*:*:*:*:*:*OR cpe:/a:microsoft:office:xp:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:office:2000:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:office:2003:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:office:2003:sp2:*:*:*:*:*:*OR cpe:/a:microsoft:works:2005:*:*:*:*:*:*:*OR cpe:/a:microsoft:works:2006:*:*:*:*:*:*:*OR cpe:/a:microsoft:works:8.0:*:*:*:*:*:*:*OR cpe:/a:microsoft:works:8.5:*:*:*:*:*:*:*OR cpe:/a:microsoft:office:2004:*:*:*:*:*:*:* Denotes that component is vulnerable |
Oval Definitions |
|
BACK |