CVE-2009-0221: Buffer Overflow
Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0221?
CVE-2009-0221 has a critical severity rating as it allows remote code execution.
How do I fix CVE-2009-0221?
To fix CVE-2009-0221, users should apply the latest patches from Microsoft for PowerPoint 2002 and 2003.
Which versions of Microsoft PowerPoint are affected by CVE-2009-0221?
CVE-2009-0221 affects Microsoft Office PowerPoint 2002 SP3 and 2003 SP3.
What type of attack is associated with CVE-2009-0221?
CVE-2009-0221 is associated with remote code execution attacks via malicious PowerPoint files.
Can CVE-2009-0221 be exploited without user interaction?
Yes, CVE-2009-0221 can be exploited without user interaction if a user opens a malicious PowerPoint file.