ZDI-CAN-20982: ZDI-24-976: Microsoft Office PowerPoint GLB File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office PowerPoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20982?
The severity of ZDI-CAN-20982 is critical, as it allows for remote code execution via malicious PowerPoint files.
How do I fix ZDI-CAN-20982?
To fix ZDI-CAN-20982, ensure that you have installed the latest security updates from Microsoft for Office PowerPoint.
Who is affected by ZDI-CAN-20982?
Users of Microsoft Office PowerPoint are affected by ZDI-CAN-20982 if they open malicious files or visit malicious pages.
What are the symptoms of ZDI-CAN-20982 exploitation?
Exploitation of ZDI-CAN-20982 may lead to unexpected application behavior, including the execution of unauthorized code.
Is user interaction required for ZDI-CAN-20982?
Yes, user interaction is required for ZDI-CAN-20982 as the target must open a malicious file or visit a compromised webpage.