CVE-2010-2572
published 2010-11-10CVE-2010-2572: Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka…
PriorityP276high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-22
Exploited in the wild
EPSS
62.60%
99.1th percentile
Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | powerpoint | — | — |
| microsoft | powerpoint | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition is parsing a crafted PowerPoint 95 document format in Microsoft PowerPoint 2002 SP3 and 2003 SP3; inspect incoming .ppt files for PowerPoint 95 format markers as a potential attack vector ↗
- ·Only Microsoft PowerPoint 2002 SP3 and 2003 SP3 are confirmed affected; other versions are not listed as vulnerable ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qrqx-wqch-hjh4: Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document,
ghsa_unreviewed·2022-05-14
CVE-2010-2572 [HIGH] CWE-119 GHSA-qrqx-wqch-hjh4: Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document,
Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
VulnCheck
Microsoft PowerPoint Buffer Overflow Vulnerability
vulncheck·2010·CVSS 7.8
CVE-2010-2572 [HIGH] CWE-119 Microsoft PowerPoint Buffer Overflow Vulnerability
Microsoft PowerPoint Buffer Overflow Vulnerability
Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.
Affected: Microsoft PowerPoint
Required Action: Apply updates per vendor instructions.
Exploitation References: https://unit42.paloaltonetworks.com/scarlet-mimic-years-long-espionage-targets-minority-activists/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-22
CISA
Microsoft PowerPoint Buffer Overflow Vulnerability
cisa·2022-06-08·CVSS 7.8
CVE-2010-2572 [HIGH] CWE-119 Microsoft PowerPoint Buffer Overflow Vulnerability
Vulnerability: Microsoft PowerPoint Buffer Overflow Vulnerability
Affected: Microsoft PowerPoint
Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-2572
Remediation Due Date: 2022-06-22
No detection rules found.
Unit42
Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
blogs_unit42·2016-01-24
Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
Threat Research Center
Threat Research
Malware
## Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
Robert Falcone
Jen Miller-Osborn
Published: January 24, 2016
Malware
Threat Research
Android
Apple
BrutishCommand
CallMe
Cyber espionage
Cyber Threat Alliance
Cybersecurity
Espionage
FakeM
Mac OS X
Microsoft
MobileOrder
Psylo
Scarlet Mimic
SkiBoot Loader
SubtractThis
Trojans
## Executive Summary
Over the past seven months, Unit 42 has been investigating a series of attacks we attribute to a group we have code named “Scarlet Mimic.” The attacks began over four years ago and their targeting pattern suggests that this adversary’s primary mission is to gather information about minority rights activists. We do not have evidence directly linking
Unit42
Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
blogs_unit42·2016-01-24
Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
## Executive Summary
Over the past seven months, Unit 42 has been investigating a series of attacks we attribute to a group we have code named “Scarlet Mimic.” The attacks began over four years ago and their targeting pattern suggests that this adversary’s primary mission is to gather information about minority rights activists. We do not have evidence directly linking these attacks to a government source, but the information derived from these activities supports an assessment that a group or groups with motivations similar to the stated position of the Chinese government in relation to these targets is involved.
The goal of this report is to expose the tools, tactics and infrastructure deployed by Scarlet Mimic in order to increase awareness of this threat and decrease its operational
Zscaler
Zscaler provides Protection During MS Patch Cycle|11-09-2010
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler provides Protection During MS Patch Cycle|11-09-2010
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.us-cert.gov/cas/techalerts/TA10-313A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-088https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12195http://www.us-cert.gov/cas/techalerts/TA10-313A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-088https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12195https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-2572
2010-11-10
Published
2022-06-08
Added to CISA KEV
Exploited in the wild