First published: Wed Aug 09 2006(Updated: )
Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft PowerPoint 2010 | =2000 | |
Microsoft PowerPoint 2010 | =2000 | |
Microsoft PowerPoint 2010 | =2000 | |
Microsoft PowerPoint 2010 | =2000 | |
Microsoft PowerPoint 2010 | =2000-sp2 | |
Microsoft PowerPoint 2010 | =2000-sp3 | |
Microsoft PowerPoint 2010 | =2000-sr1 | |
Microsoft PowerPoint 2010 | =2001 | |
Microsoft PowerPoint 2010 | =2002 | |
Microsoft PowerPoint 2010 | =2002-sp1 | |
Microsoft PowerPoint 2010 | =2002-sp2 | |
Microsoft PowerPoint 2010 | =2002-sp3 | |
Microsoft PowerPoint 2010 | =2003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3449 is considered a critical vulnerability due to the potential for arbitrary command execution.
To fix CVE-2006-3449, ensure that you have installed the latest security updates for Microsoft PowerPoint.
CVE-2006-3449 affects Microsoft PowerPoint 2000 through 2003 in various service pack versions.
CVE-2006-3449 can be exploited via user-assisted remote attacks through malformed BIFF files in PowerPoint presentations.
Exploiting CVE-2006-3449 may allow an attacker to execute arbitrary commands on the victim's system.