CVE-2006-0004
Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 31.51% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/office
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/18865
- http://securitytracker.com/id?1015632
- http://www.kb.cert.org/vuls/id/963628US Government Resource
- http://www.securityfocus.com/bid/16634
- http://www.vupen.com/english/advisories/2006/0579
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-010
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24490
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1555
- http://secunia.com/advisories/18865
- http://securitytracker.com/id?1015632
- http://www.kb.cert.org/vuls/id/963628US Government Resource
- http://www.securityfocus.com/bid/16634
- http://www.vupen.com/english/advisories/2006/0579
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-010
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24490
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1555
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.