cbcvebase.
CVE-2010-0033
published 2010-02-10

CVE-2010-0033: Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka…

PriorityP265critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
51.07%
98.8th percentile
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."

Affected

1 ranges
VendorProductVersion rangeFixed in
microsoftpowerpoint

Detection & IOCsextracted from sources · hover to see the quote

filenamemsf.ppt
other0x30056471
other0x3003c767
other0x300566d1
otherTextBytesAtom record tag 0xfa8
otherTextBytesAtom length field overwritten to 0xffffffff
otherSEHOffset 132 bytes
pathPowerPoint Document
pathCurrent User
otherheaderToken 0xe391c05f (unencrypted CurrentUserAtom)
  • ·The exploit only works on Windows Vista and later; attempting exploitation on Windows XP or earlier will not reach the vulnerable code path.
  • ·The pop/pop/ret gadget addresses are hardcoded per PPTVIEW.exe patch level; the ASLR-affected gdiplus.dll target was explicitly commented out as unreliable.
  • ·Affected products are PowerPoint Viewer distributed with Office 2003 SP3 and earlier, and Office 2004 for Mac.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.