Vulnerability Name:

CVE-2006-3449 (CCN-28025)

Assigned:2006-08-08
Published:2006-08-08
Updated:2018-10-18
Summary:Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-Disclosure Mailing List, Tue Aug 08 2006 - 15:20:27 CDT
Microsoft PowerPoint Malformed Record Memory Corruption

Source: MITRE
Type: CNA
CVE-2006-3449

Source: SREASON
Type: Third Party Advisory
1342

Source: CCN
Type: SECTRACK ID: 1016657
Microsoft Office Buffer Overflow in Processing PowerPoint Records Lets Remote Users Execute Arbitrary Code

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1016657

Source: MISC
Type: Not Applicable
http://secway.org/advisory/AD20060808.txt

Source: CCN
Type: ASA-2006-154
Windows Security Updates for August 2006 - (MS06-040 - MS06-051)

Source: CCN
Type: US-CERT VU#884252
Microsoft PowerPoint fails to properly handle malformed records

Source: CERT-VN
Type: Patch, Third Party Advisory, US Government Resource
VU#884252

Source: CCN
Type: Microsoft Security Bulletin MS06-048
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (922968)

Source: CCN
Type: Microsoft Security Bulletin MS06-062
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (922581)

Source: BUGTRAQ
Type: UNKNOWN
20060808 Microsoft PowerPoint Malformed Record Memory Corruption

Source: BID
Type: Third Party Advisory, VDB Entry
19341

Source: CCN
Type: BID-19341
Microsoft Powerpoint Remote Code Execution Vulnerability

Source: CCN
Type: US-CERT Technical Cyber Security Alert TA06-220A
Microsoft Windows, Office, and Internet Explorer Vulnerabilities

Source: CERT
Type: Patch, Third Party Advisory, US Government Resource
TA06-220A

Source: MS
Type: UNKNOWN
MS06-048

Source: XF
Type: UNKNOWN
powerpoint-record-code-execution(28025)

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:348

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:powerpoint:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2000:*:*:ja:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2000:*:*:ko:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2000:*:*:zh:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2000:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2000:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2000:sr1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2001:*:*:*:*:mac_os:*:*
  • OR cpe:/a:microsoft:powerpoint:2002:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2002:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2002:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2002:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2003:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:powerpoint:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2002:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint:2003:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:348
    V
    Microsoft PowerPoint Malformed Records Vulnerability
    2012-05-28
    BACK
    microsoft powerpoint 2000
    microsoft powerpoint 2000
    microsoft powerpoint 2000
    microsoft powerpoint 2000
    microsoft powerpoint 2000 sp2
    microsoft powerpoint 2000 sp3
    microsoft powerpoint 2000 sr1
    microsoft powerpoint 2001
    microsoft powerpoint 2002
    microsoft powerpoint 2002 sp1
    microsoft powerpoint 2002 sp2
    microsoft powerpoint 2002 sp3
    microsoft powerpoint 2003
    microsoft powerpoint 2000
    microsoft powerpoint 2002
    microsoft powerpoint 2003