>> Microsoft PowerPoint Malformed Record Code Execution Vulnerability (MS06-058)
Title : Microsoft PowerPoint Malformed Record Code Execution Vulnerability (MS06-058) VUPEN ID : VUPEN/ADV-2006-3794 CVE ID : CVE-2006-4694
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-09-27
Technical Description
A vulnerability has been identified in Microsoft PowerPoint, which could be exploited by attackers to take complete control of an affected system. This flaw is due to a memory corruption error when handling a malformed presentation, which could be exploited by attackers to execute arbitrary commands by tricking a user into opening a specially crafted document.
Note : This zero-day vulnerability is currently being exploited in the wild by Trojan.Controlppt.W and Trojan.Controlppt.X (also known as PPDropper.F and Exploit-PPT.d).