Microsoft released Advisory 969136 on April 2, 2009 due to a vulnerability in Microsoft Office PowerPoint that could allow remote code execution.
| References | Identification |
|---|---|
|
CVE Reference |
CVE-2009-0556 [1] |
|
Microsoft Knowledge Base Article |
969136 [2] |
This advisory discusses the following software.
| Affected Software |
|---|
|
Microsoft Office PowerPoint 2000 Service Pack 3 |
|
Microsoft Office PowerPoint 2002 Service Pack 3 |
|
Microsoft Office PowerPoint 2003 Service Pack 3 |
|
Microsoft Office 2004 for Mac |
| Non-affected Software |
|---|
|
Microsoft Office PowerPoint 2007 |
|
Microsoft Office PowerPoint 2007 Service Pack 1 |
|
Microsoft Office PowerPoint Viewer 2003 |
|
Microsoft Office PowerPoint Viewer 2007 |
|
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats |
|
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 |
|
Microsoft Office 2008 for Mac |
|
Open XML File Format Converter for Mac |
Microsoft has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they help block known attack vectors. When a workaround reduces functionality, it is identified in the following section.
Do not open or save Office files that you receive from un-trusted sources or that are received unexpectedly from trusted sources. [3] |
Use the Microsoft Office Isolated Conversion Environment (MOICE) when opening files from unknown or untrusted sources [4] |
Use Microsoft Office File Block policy to block the opening of Office 2003 and earlier documents from unknown or untrusted sources and locations [8] |
Links:
[1] http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0556
[2] http://support.microsoft.com/kb/969136
[3] http://support.wavesco.com/javascript:Toggle('s9l3-ECH')
[4] http://support.wavesco.com/javascript:Toggle('s9l3-EGH')
[5] http://www.microsoft.com/downloads/details.aspx?FamilyID=941b3470-3ae9-4aee-8f43-c6bb74cd1466&displaylang=en
[6] http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us
[7] http://support.microsoft.com/kb/935865
[8] http://support.wavesco.com/javascript:Toggle('s9l3-EEBAC')
[9] http://support.microsoft.com/kb/922848
[10] http://www.microsoft.com/technet/security/advisory/969136.mspx