CVE-2006-3660
published 2006-07-18CVE-2006-3660: Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of…
PriorityP341high7.6CVSS 2.0
AVNACHAuNCCICAC
EXPLOIT
EPSS
18.24%
96.9th percentile
Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | powerpoint | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
50 4B 03 04 14 00 00 00 08 00 9D A9 EB 34 32 BE F8 2F C7 2D
- →Malicious PowerPoint file (dawn.ppt) embedded in a ZIP/PK container (magic bytes 50 4B 03 04) triggers memory corruption in powerpnt.exe when the file is closed; monitor for anomalous PowerPoint process crashes or memory faults on file close. ↗
- →The crafted file uses a ZIP-wrapped .ppt payload (filename 'dawn.ppt'); inspect archive contents for embedded .ppt files with this name or similar obfuscated names. ↗
- ·It is unclear whether the three PoC exploit files pertain to newly discovered vulnerabilities or previously disclosed issues; CVE-2006-3660 may overlap with CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590. ↗
- ·Arbitrary code execution via this vulnerability has not been confirmed; only crashes have been demonstrated. ↗
- ·Microsoft PowerPoint 2003 is the confirmed vulnerable version; other versions may also be affected but are unconfirmed. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h95h-vwpr-fwvm: Unspecified vulnerability in mso
ghsa_unreviewed·2022-05-01·CVSS 5.1
CVE-2006-3655 [MEDIUM] GHSA-h95h-vwpr-fwvm: Unspecified vulnerability in mso
Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
GHSA
GHSA-9p5j-hvvw-r99g: Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt
ghsa_unreviewed·2022-05-01·CVSS 5.1
CVE-2006-3660 [MEDIUM] GHSA-9p5j-hvvw-r99g: Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt
Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
GHSA
GHSA-p2jj-q38r-qrq2: Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which
ghsa_unreviewed·2022-05-01·CVSS 5.1
CVE-2006-3656 [MEDIUM] GHSA-p2jj-q38r-qrq2: Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/21061http://www.securityfocus.com/archive/1/440106/30/30/threadedhttp://www.securityfocus.com/archive/1/440370/100/0/threadedhttp://www.securityfocus.com/archive/1/440867/100/0/threadedhttp://www.securityfocus.com/bid/18993http://www.vupen.com/english/advisories/2006/2815https://exchange.xforce.ibmcloud.com/vulnerabilities/27783http://secunia.com/advisories/21061http://www.securityfocus.com/archive/1/440106/30/30/threadedhttp://www.securityfocus.com/archive/1/440370/100/0/threadedhttp://www.securityfocus.com/archive/1/440867/100/0/threadedhttp://www.securityfocus.com/bid/18993http://www.vupen.com/english/advisories/2006/2815https://exchange.xforce.ibmcloud.com/vulnerabilities/27783
2006-07-18
Published