PPDropper.B Trojan.
Bloodhound.Exploit.79
Vulnerability details
Advisory: SB2006071701 - Remote code execution in Microsoft PowerPoint
Vulnerable component: Microsoft PowerPoint
CVE-ID: CVE-2006-3590
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:F/RL:O/RC:C
CWE-ID: CWE-119 - Memory corruption
Description:
The vulnerability allows a remote user to execute arbitrary code on the target system.
The weakness is due to memory corruption in mso.dll. By persuading the victim to open a specially crafted PPT file, containing a malformed shape container, a remote attacker can execute arbitrary code on vulnerable system.
Successful exploitation of the vulnerability results in complete compromise of vulnerable system.
Note: this vulnerability was being actively exploited.
External links:
https://blogs.securiteam.com/index.php/archives/508
http://www.microsoft.com/technet/security/Bulletin/MS06-048.mspx
http://www.microsoft.com/technet/security/advisory/922970.mspx
http://blogs.technet.com/msrc/archive/2006/07/14/441893.aspx
https://www.symantec.com/security_response/writeup.jsp?docid=2006-092614-1828-99&tabid=2
https://ae.norton.com/security_response/print_writeup.jsp?docid=2006-092614-1828-99
https://forums.whatthetech.com/index.php?showtopic=66223