cbcvebase.
CVE-2006-5296
published 2006-10-16

CVE-2006-5296: PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted…

PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
25.55%
97.7th percentile
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.

Affected

1 ranges
VendorProductVersion rangeFixed in
microsoftpowerpoint

Detection & IOCsextracted from sources · hover to see the quote

otherTrojan.PPDropper.G
  • Malicious .PPT file triggers a null pointer dereference / call through ECX at offset 3001afbc in PowerPoint 2003 (fully patched); monitor for crashes or abnormal control flow in POWERPNT.EXE when opening .PPT files
  • Crafted .PPT file begins with the OLE2 compound-document magic bytes D0 CF 11 E0 A1 B1 1A E1; scan incoming .PPT attachments for this header combined with anomalous stream sizes or overflow-indicative padding
  • Trojan.PPDropper.G is the malware family associated with in-the-wild exploitation of this PowerPoint vulnerability; use this name as a detection signature in AV/EDR tooling
  • ·NVD notes uncertainty about whether CVE-2007-0913 (and its Trojan.PPDropper.G association) is the same issue as CVE-2006-5296 or several other related CVEs; treat the Trojan.PPDropper.G indicator with that ambiguity in mind
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.