NULL pointer dereference in Microsoft Office - CVE-2006-3435
Published: December 6, 2016
Microsoft
Microsoft Office
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability is caused by NULL pointer dereference error when parsing of a malformed slide notes field within the PowerPoint presentation. A remote attacker can create a specially crafted .ppt file, trick the victim into opening it and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability results in compromise of vulnerable system.
How to mitigate CVE-2006-3435
Microsoft Office 2003 Service Pack 1 or Service Pack 2 — Download the update (KB923091)