This application requires Javascript for optimal performance.

MS.Office.PowerPoint.Insecure.Library.Loading

Release Date

Dec 15, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a Remote Code Execution vulnerability in Microsoft PowerPoint.

The vulnerability is caused by the way the vulnerable application loads "pp7x32.dll" and "pp4x322.dll". A remote attacker can exploit it to load and execute a malicious DLL.

Affected Products

Microsoft Office 2007 Service Pack 2
Microsoft Office 2010 (32-bit editions)
Microsoft Office 2010 (64-bit editions)
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2 (KB2596843)
Microsoft PowerPoint Viewer 2007 Service Pack 2 (KB2596912)

Recommended Actions

Apply the most recent upgrades or patches from the vendor:
http://www.microsoft.com/technet/security/Bulletin/MS11-094.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-3396

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS11-094.mspx (MS-ID)

Reference: VID-30604