MS06-010: Vulnerability in PowerPoint 2000 Could Allow Information Disclosure (889167)

medium Nessus Plugin ID 20910

Synopsis

The remote version of PowerPoint is vulnerable to an information disclosure attack.

Description

The remote host contains a version of PowerPoint that is vulnerable to an information disclosure attack.

Specifically, an attacker could send a malformed PowerPoint file to a a victim on the remote host. When the victim opens the file, the attacker may be able to obtain access to the files in the Temporary Internet Files Folder of the remote host.

Solution

Microsoft has released a set of patches for PowerPoint.

See Also

https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2006/ms06-010

Plugin Details

Severity: Medium

ID: 20910

File Name: smb_nt_ms06-010.nasl

Version: 1.32

Type: local

Agent: windows

Published: 2/14/2006

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.7

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:microsoft:office, cpe:/a:microsoft:powerpoint

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Ease: No known exploits are available

Patch Publication Date: 2/14/2006

Vulnerability Publication Date: 2/14/2006

Reference Information

CVE: CVE-2006-0004

BID: 16634

MSFT: MS06-010

MSKB: 889167