9.3

CVE-2011-0655

Microsoft PowerPoint 2007 SP2 and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; PowerPoint Viewer; PowerPoint Viewer 2007 SP2; and PowerPoint Web App do not properly validate TimeColorBehaviorContainer Floating Point records in PowerPoint documents, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document containing an invalid record, aka "Floating Point Techno-color Time Bandit RCE Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Version 2004 Edition mac
Microsoft ≫ Office Version 2008 Edition mac
Microsoft ≫ Office Version 2011 Edition mac
Microsoft ≫ Office Compatibility Pack Version 2007 Update sp2
Microsoft ≫ Powerpoint Version 2010 Edition x32
Microsoft ≫ Powerpoint Version 2010 Edition x64
Microsoft ≫ Powerpoint Viewer Version 2007 Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.59% 0.974
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.us-cert.gov/cas/techalerts/TA11-102A.html
US Government Resource
http://www.securitytracker.com/id?1025340
http://www.vupen.com/english/advisories/2011/0941
Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-022
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12624