« Volver al listado

CVE-2008-0120

Estado: ModificadaAlta (9.3)—

Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-0120",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-08-13T00:41:00.000",
  "references": [
    {
      "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=739",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=121915960406986&w=2",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://secunia.com/advisories/31453",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/30552",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1020676",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA08-225A.html",
      "tags": [
        "US Government Resource"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2355",
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-051",
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5768",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=739",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=121915960406986&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/31453",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/30552",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1020676",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA08-225A.html",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2355",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-051",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5768",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka \"Memory Allocation Vulnerability.\""
    },
    {
      "lang": "es",
      "value": "Un desbordamiento de enteros en PowerPoint Viewer 2003 de Microsoft, permite a los atacantes remotos ejecutar código arbitrario por medio de un archivo de PowerPoint con un índice de imagen malformado que desencadena una corrupción de memoria, relacionados con el manejo de objetos CString, también se conoce como \"Memory Allocation Vulnerability\"."
    }
  ],
  "lastModified": "2026-06-16T22:48:58.893",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:office_powerpoint_viewer:2003:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5440EF5-462B-4BAC-AF60-44C5D649D0D7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}