CVE-2006-3656
published 2006-07-18CVE-2006-3656: Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers…
PriorityP421low2.6CVSS 2.0
AVNACHAuNCNIPAN
EXPLOIT
EPSS
20.52%
97.2th percentile
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | powerpoint | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
50 4B 03 04 14 00 00 00 08 00 9A A9 EB 34 2C E4 59 27 E3 2D 00 00 00 8C 00 00 07 00 00 00 6D 6D 65 2E 70 70 74
- →Memory corruption is triggered specifically when the crafted .ppt file is closed in PowerPoint 2003, not on open — monitor for crashes/access violations in POWERPNT.EXE during file-close operations on .ppt files. ↗
- →The PoC file is named 'mme.ppt' (bytes 0x6D 0x6D 0x65 0x2E 0x70 0x70 0x74 embedded in the payload); hunt for this filename in endpoint telemetry. ↗
- →The malicious .ppt file begins with the PK ZIP magic bytes (50 4B 03 04), indicating it uses a ZIP-based container format; inspect .ppt files with this header for anomalies. ↗
- ·The vulnerability is unspecified and its exact relationship to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590 is unclear; the same PoC file may overlap with those CVEs. ↗
- ·It is unconfirmed whether the vulnerability allows arbitrary code execution or only a crash/denial-of-service. ↗
- ·Only Microsoft PowerPoint 2003 was confirmed tested; other versions may also be affected. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h95h-vwpr-fwvm: Unspecified vulnerability in mso
ghsa_unreviewed·2022-05-01·CVSS 5.1
CVE-2006-3655 [MEDIUM] GHSA-h95h-vwpr-fwvm: Unspecified vulnerability in mso
Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
GHSA
GHSA-9p5j-hvvw-r99g: Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt
ghsa_unreviewed·2022-05-01·CVSS 5.1
CVE-2006-3660 [MEDIUM] GHSA-9p5j-hvvw-r99g: Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt
Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
GHSA
GHSA-p2jj-q38r-qrq2: Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which
ghsa_unreviewed·2022-05-01·CVSS 5.1
CVE-2006-3656 [MEDIUM] GHSA-p2jj-q38r-qrq2: Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
No detection rules found.
http://downloads.securityfocus.com/vulnerabilities/exploits/PP2003sp2patched_fr_exploit-method.txthttp://packetstormsecurity.org/0607-exploits/mspp-poc3.txthttp://secunia.com/advisories/21061http://www.securityfocus.com/archive/1/440108/100/0/threadedhttp://www.securityfocus.com/archive/1/440370/100/0/threadedhttp://www.securityfocus.com/archive/1/440867/100/0/threadedhttp://www.securityfocus.com/bid/18993http://www.securityfocus.com/bid/19229http://www.vupen.com/english/advisories/2006/2815https://exchange.xforce.ibmcloud.com/vulnerabilities/27781https://exchange.xforce.ibmcloud.com/vulnerabilities/27782http://downloads.securityfocus.com/vulnerabilities/exploits/PP2003sp2patched_fr_exploit-method.txthttp://packetstormsecurity.org/0607-exploits/mspp-poc3.txthttp://secunia.com/advisories/21061http://www.securityfocus.com/archive/1/440108/100/0/threadedhttp://www.securityfocus.com/archive/1/440370/100/0/threadedhttp://www.securityfocus.com/archive/1/440867/100/0/threadedhttp://www.securityfocus.com/bid/18993http://www.securityfocus.com/bid/19229http://www.vupen.com/english/advisories/2006/2815https://exchange.xforce.ibmcloud.com/vulnerabilities/27781https://exchange.xforce.ibmcloud.com/vulnerabilities/27782
2006-07-18
Published