Clicky

Pages

Showing posts with label CVE-2009-0556. Show all posts
Showing posts with label CVE-2009-0556. Show all posts

Tuesday, December 21, 2010

Dec 21 CVE-2009-0556 (corrected CVE) Christmas Messages.pps with stolen cert from Syniverse from nicholas.bennett53@hotmail.com

Common Vulnerabilities and Exposures (CVE)number

CVE-2009-0556 Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."

CVE-2010-2572  Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."

Update

I would like to have a more technical analysis and identification of CVE in addition to this preliminary testing, so if you do it, please send over, I will add :) thank you

Comments: Shih-hao Weng (thank you) noted that he thinks it is CVE-2009-0556.  I tested, indeed - the patch for CVE-2009-0556 (MS09-017 KB957784 May 12 2009) fixes it.

The only patch from Microsoft Updates that is automatically available and fixes it these days is MS10-088, which is for CVE-2010-2572. However MS10-088 replaced earlier patches, including MS09-017 ( CVE-2009-0556 ). CVE-2009-0556 was used a in a lot in malicious attachments in the past 

  You cannot automatically install MS09-017 via Microsoft Updates - see below but if you find it and install manually (for Sp3 MS09-017 KB957784 May 12 2009)MS10-004 KB976881 Feb 4, 2010 would also fix it.

Everything in the post stays the same - except the CVE number changes to CVE-2009-0556 and the patches that will keep you safe are 

For Office 2003 SP3

MS10-088, which is for CVE-2010-2572 OR MS09-017 KB957784  OR MS10-004 KB976881 Feb 4, 2010


  General File Information

File      Christmas Messages.pps 

MD5   51d3e2bd306495de50bfd0f2f4e19ae9

 SHA1  7edd6beff619f86fae7f94a60ac4bcdb04473dfb 

Size :    838144 bytes

Type:    PPS
Distribution: Email attachment
                                       

Download

Wednesday, July 21, 2010

Jul 15 CVE-2009-0556 PPT North Korean Nuclear Update from david.alton33@hotmail.com


Download  Nuclear_report.pps 71803d893ed7d052fdb58f10da200fe9 as a password protected archive (contact me if you need the password)

From: David Alton [mailto:david.alton33@hotmail.com]
Sent: Thursday, July 15, 2010 4:03 AM
To: xxxxxxxxxx
Subject: North Korean Nuclear Update.

 
Recently U.S Secretary of State Hillary Clinton has said North
Korea as many as six nuclear weapons.
 
Attached please find Koreatimes`s article about North Korea`s
Nuclear issue...   I believe it could be of your interest and helpful for reviewing
the NK Nuclear activities.
 ___________________________________
Your E-mail and More On-the-Go. Get Windows Live Hotmail Free. Sign up now.

 File Nuclear_report.pps received on 2010.07.21 11:33:22 (UTC)
http://www.virustotal.com/analisis/3bb1d1d441ab7412ca429ec2db6dbcf48e2b19323bf589d37698e76dc305044f-1279712002
Result: 11/42 (26.2%)
BitDefender    7.2    2010.07.21    Exploit.PPT.Gen
Emsisoft    5.0.0.34    2010.07.21    Exploit.MSPPoint.Agent!IK
F-Secure    9.0.15370.0    2010.07.21    Exploit.PPT.Gen
GData    21    2010.07.21    Exploit.PPT.Gen
Ikarus    T3.1.1.84.0    2010.07.21    Exploit.MSPPoint.Agent
Kaspersky    7.0.0.125    2010.07.21    Exploit.MSPPoint.Agent.x
McAfee-GW-Edition    2010.1    2010.07.21    Heuristic.BehavesLike.Exploit.P97.CodeExec.PGPG
Norman    6.05.11    2010.07.20    ShellCode.D
nProtect    2010-07-21.01    2010.07.21    Exploit.PPT.Gen
Sophos    4.55.0    2010.07.21    Troj/ExpPPT-A
TrendMicro-HouseCall    9.120.0.1004    2010.07.21    HEUR_OLEXP.B
Additional information
File size: 838144 bytes
MD5...: 71803d893ed7d052fdb58f10da200fe9

Headers
X-Originating-IP: [119.247.93.218]
From: David Alton
To: xxxxxxxxxxxx
Subject: North Korean Nuclear Update.
Date: Thu, 15 Jul 2010 20:03:21 +1200
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 15 Jul 2010 08:03:21.0286 (UTC) FILETIME=[31184E60:01CB23F4]

Hostname:    119247093218.ctinets.com
ISP:    City Telecom (H.K.) Ltd.
Organization:    City Telecom (H.K.) Ltd.
Type:    Broadband
Assignment:    Static IP
Country:    Hong Kong hk flag
City:    Tin Shui Wai
  

Thursday, July 8, 2010

Jul 8 CVE-2009-0556 China and the Cheonan Incident vargas43@hotmail.com


 Download  a362abe459c574b1984640316219c818 Presentations.pps as a password protected archive (contact me if you need the password)



From: Jorge Vargas [mailto:jorge.vargas43@hotmail.com]
Sent: Thursday, July 08, 2010 3:02 AM
To: XXXXXXXXXXX
Subject: China and the Cheonan Incident

China and the Cheonan Incident 
Author : David Kang Published
The Chinese are facing widespread criticism for their behavior following the Cheonan incident
______________________________________
Hotmail: Free, trusted and rich email service. Get it now.

 File Presentations.pps received on 2010.07.10 17:11:12 (UTC)
http://www.virustotal.com/analisis/e22805d4f845c42d801e6b2b87782716a01c2db0553e2b4da7eda355ba28cdcf-1278781872
Result: 8/41 (19.52%)
BitDefender    7.2    2010.07.10    Exploit.PPT.Gen
F-Secure    9.0.15370.0    2010.07.09    Exploit.PPT.Gen
GData    21    2010.07.10    Exploit.PPT.Gen
McAfee-GW-Edition    2010.1    2010.07.05    Heuristic.BehavesLike.Exploit.P97.CodeExec.PGPG
Norman    6.05.11    2010.07.10    ShellCode.D
nProtect    2010-07-10.01    2010.07.10    Exploit.PPT.Gen
Sophos    4.55.0    2010.07.10    Troj/ExpPPT-A
TrendMicro-HouseCall    9.120.0.1004    2010.07.10    HEUR_OLEXP.B
Additional information
File size: 838144 bytes
MD5...: a362abe459c574b1984640316219c818

Headers

Received: from SNT127-W1 ([65.55.90.136]) by snt0-omc3-s15.snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
     Thu, 8 Jul 2010 00:01:36 -0700
Message-ID:
Return-Path: jorge.vargas43@hotmail.com
Content-Type: multipart/mixed;
    boundary="_dafedb01-4726-4c6a-ab40-94312905e44c_"
X-Originating-IP: [69.64.56.19]
From: Jorge Vargas
To: xxxxxxxxxxxx
Subject: China and the Cheonan Incident
Date: Thu, 8 Jul 2010 08:01:36 +0100
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 08 Jul 2010 07:01:36.0526 (UTC) FILETIME=[67FE8AE0:01CB1E6B]

Hostname: usloft1344.serverloft.com
ISP: Hosting Solutions International
Organization: INTERLAND
Proxy: Suspected network sharing device.
Country: United States  
State/Region: Georgia
City: Atlanta

Thursday, April 2, 2009

April 02, 2009 CVE-2009-0556 PPT - 0 Day One of the first samples. Cooperative threat reduction

Link updated: Jan 18, 2023
Download infected ppt files  Cooperative Threat Reduction briefing.PPT - b622b9e294647277dc40205dcf27e086 and CTR_talk.PPT - 0e1fc785eff45ff0b140dbf61abf3eab

 (password protected archive, see my profile for email address if you need the password

From: XXXXXX@gmail.com
Sent: Thursday, April 02, 2009 3:59 AM
To: XXXXXXXX
Subject: Cooperative Threat Reduction
I've attached the CTR concept paper.  Feel free to circulate it. We very much look forward to the comments of you and your colleagues.
Best regards,
[name and contact info removed]

Message received on April 2, 2009

Attachment 1
Cooperative Threat Reduction briefing.PPT - b622b9e294647277dc40205dcf27e086
Virustotal scan on April 2, 2009
http://www.virustotal.com/analisis/dcf59752b35afa4034cc6e99e24ab9b8

File Cooperative_Threat_Reduction_brie received on 2009.04.02 22:22:40 (UTC)
Current status: finished
Result: 2/40 (5.00%)
Antivirus     Version     Last Update     Result
McAfee-GW-Edition     6.7.6     2009.04.01     OLE2.LooksLike.Suspicious.gen
Norman     6.00.06     2009.04.02     ShellCode.A
 Additional information
File size: 838144 bytes
MD5...: b622b9e294647277dc40205dcf27e086