cbcvebase.
CVE-2006-3660
published 2006-07-18

CVE-2006-3660: Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of…

PriorityP341high7.6CVSS 2.0
AVNACHAuNCCICAC
EXPLOIT
EPSS
18.24%
96.9th percentile
Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.

Affected

1 ranges
VendorProductVersion rangeFixed in
microsoftpowerpoint

Detection & IOCsextracted from sources · hover to see the quote

filenamedawn.ppt
processpowerpnt.exe
bytes
50 4B 03 04 14 00 00 00 08 00 9D A9 EB 34 32 BE F8 2F C7 2D
  • Malicious PowerPoint file (dawn.ppt) embedded in a ZIP/PK container (magic bytes 50 4B 03 04) triggers memory corruption in powerpnt.exe when the file is closed; monitor for anomalous PowerPoint process crashes or memory faults on file close.
  • The crafted file uses a ZIP-wrapped .ppt payload (filename 'dawn.ppt'); inspect archive contents for embedded .ppt files with this name or similar obfuscated names.
  • ·It is unclear whether the three PoC exploit files pertain to newly discovered vulnerabilities or previously disclosed issues; CVE-2006-3660 may overlap with CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590.
  • ·Arbitrary code execution via this vulnerability has not been confirmed; only crashes have been demonstrated.
  • ·Microsoft PowerPoint 2003 is the confirmed vulnerable version; other versions may also be affected but are unconfirmed.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.