Security 10748 Published by

Microsoft updated MS11-036 - Important: Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2545814) to version 1.1



MS11-036 - Important: Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (2545814) - Version:1.1
Severity Rating: Important - Revision Note: V1.1 (May 17, 2011): Removed an erroneous note from the Affected Software table pertaining to security updates KB2535818 and KB2540162 for Microsoft PowerPoint 2007 Service Pack 2.

Summary: This security update resolves two privately reported vulnerabilities in Microsoft PowerPoint. The vulnerabilities could allow remote code execution if a user opens a specially crafted PowerPoint file. An attacker who successfully exploited either of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1269 and CVE-2011-1270.
Read more