SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-0022

Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v.

HIGH 7.6EPSS 14.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 14.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.

CVSS 2.0
7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS
14.54% probability · 96th percentile
CISA KEV
Not listed
Affected
microsoft/powerpoint
Source
secure@microsoft.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.