Short Name |
HTTP:STC:PPT-LONGNAME |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
HTTP |
Keywords |
Microsoft Powerpoint Long Filename Overflow |
Release Date |
2010/02/09 |
Update Number |
1602 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Microsoft PowerPoint. An attacker can trick a victim into visiting a hostile Web site, which if successful, can cause a buffer overflow on the victim's machine; with the result that the attacker can gain the same user rights as the local victim user.
Microsoft PowerPoint is prone to a remote code-execution vulnerability. An attacker can exploit this issue by enticing a victim to open a malicious PowerPoint file. Successful exploits would allow the attacker to execute arbitrary code in the context of the currently logged-in user.