First published: Tue May 12 2009(Updated: )
Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office PowerPoint | =2003-sp3 | |
Microsoft Office PowerPoint | =2002-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0221 has a critical severity rating as it allows remote code execution.
To fix CVE-2009-0221, users should apply the latest patches from Microsoft for PowerPoint 2002 and 2003.
CVE-2009-0221 affects Microsoft Office PowerPoint 2002 SP3 and 2003 SP3.
CVE-2009-0221 is associated with remote code execution attacks via malicious PowerPoint files.
Yes, CVE-2009-0221 can be exploited without user interaction if a user opens a malicious PowerPoint file.