exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ms01-002

ms01-002
Posted Jan 26, 2001

Microsoft Security Bulletin MS01-002 - A serious vulnerability in Microsoft Powerpoint allows remote code execution when a user is enticed into visiting a malicious website, viewing a specially crafted email message, or opening a malformed PowerPoint 2000 file. A parsing routine executed when PowerPoint 2000 opens files contains a buffer overflow vulnerability which allows attackers to crash or cause arbitrary code to run on the user's machine. Microsoft FAQ on this issue available here.

tags | remote, overflow, arbitrary, code execution
SHA-256 | 01c54da2fbcf20212d99f8f315627f0b72ecbe4d335a180d1785676c2723b7d8

ms01-002

Change Mirror Download
The following is a Security  Bulletin from the Microsoft Product Security
Notification Service.

Please do not reply to this message, as it was sent from an unattended
mailbox.
********************************

-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------
Title: PowerPoint File Parsing Vulnerability
Date: January 22, 2001
Revised: January 25, 2001 (Version 2.0)
Software: PowerPoint 2000
Impact: Execution of Arbitrary Code
Bulletin: MS01-002

Microsoft encourages customers to review the Security Bulletin at:
http://www.microsoft.com/technet/security/bulletin/ms01-002.asp
- ----------------------------------------------------------------------

Revisions:
==========
On January 22, Microsoft released the original version of this
bulletin, to advise customers of the availability of a patch that
eliminates a security vulnerability in Microsoft PowerPoint 2000.
However, the originally released patch did not include the entirety
of the fixes related to this vulnerability. An updated patch has been
made available that corrects the orginally reported vulnerability.
Customers who downloaded and installed the original patch should
download and install the updated patch. Instructions for determining
the current version of the patch and for installing the updated patch
are available via the Patch Availability URL in the security
bulletin referenced above.

The bulletin has also been updated to more accurately reflect the
conditions under which this vulnerability may be exploited.

Issue:
======
A parsing routine that is executed when PowerPoint 2000 opens files
contains an unchecked buffer. If an attacker inserted specially
chosen data into a PowerPoint file and could entice another user into
opening the file on his machine, the data would overrun the buffer,
causing either of two effects. In the less serious case, overrunning
the data would cause PowerPoint to fail, but wouldn't have any other
effect. In the more serious case, overrunning the buffer could allow
the attacker to cause code of her choice to run on the user's
machine. The code could take any action that the user himself could
take on the machine. Typically, this would enable the attacker's code
to add, change or delete data, communicate with a remote server, or
take other actions.


Mitigating Factors:
===================
- The user would need to be enticed into either opening the
malformed PowerPoint 2000 file, visiting a malicious website,
or viewing a specially crafted html email message.


Patch Availability:
===================
- A patch is available to fix this vulnerability. Please read
Security Bulletin MS01-002 at:
http://www.microsoft.com/technet/security/bulletin/ms01-002.asp
for information on obtaining this patch.


Acknowledgment:
===============
- Dave Aitel and Frank Swiderski of @Stake (http://www.atstake.com)


- ----------------------------------------------------------------------


THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED
"AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL
WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT
SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY
DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL,
CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF
MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE
POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION
OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO
THE FOREGOING LIMITATION MAY NOT APPLY.


-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.3

iQEVAwUBOnDriY0ZSRQxA/UrAQEewQf/SqdfrJ3q8+tjXoGXsZ6cf8xIpI4XvQvm
NUQRTdNtTOv50FtcS15xLwlEzGPmLjOCBxpTKcQd/Fl3wlSdtg5qpbXkhma1kqb0
B6SaWw6uGYxWiDw5eW/9p294VUXnIK5/5OlbNSwDkDSfpRuvRkgvSIY1KfmPg51c
dKMpvIAU6jIqXvp/wMfyH1ZFA4O92eeZa3cXRcAjws2i8E2/W9DsIjoe2hLQZTVv
1Z/krUQ5cEO9mHyyP3KUEgo1UEn41aT9QsQq/5W8HA/maYLOjqbR0nUjeohVjHt/
r4S5dljK2fIDZ6/otGuu0rfWHgASIf3lUuH5fbqpsAezioHhBvEhWQ==
=G5xB
-----END PGP SIGNATURE-----

*******************************************************************
You have received this e-mail bulletin as a result of your registration
to the Microsoft Product Security Notification Service. You may
unsubscribe from this e-mail notification service at any time by sending
an e-mail to MICROSOFT_SECURITY-SIGNOFF-REQUEST@ANNOUNCE.MICROSOFT.COM
The subject line and message body are not used in processing the request,
and can be anything you like.

To verify the digital signature on this bulletin, please download our PGP
key at http://www.microsoft.com/technet/security/notify.asp.

For more information on the Microsoft Security Notification Service
please visit http://www.microsoft.com/technet/security/notify.asp. For
security-related information about Microsoft products, please visit the
Microsoft Security Advisor web site at http://www.microsoft.com/security.
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close