Intrusion Prevention

MS.PowerPoint.TextHeaderAtom.Record.Code.Execution

Description

This indicates an attempt to exploit a remote code execution vulnerability in Microsoft PowerPoint.
The vulnerability results from insecure code in ppcore.dll. It can be exploited via a crafted Microsoft PowerPoint document. A successful exploit may allow remote attackers to execute arbitrary code.

Affected Products

Microsoft PowerPoint 2002 Service Pack 3
Microsoft PowerPoint 2003 Service Pack 3
Microsoft PowerPoint 2007 Service Pack 2
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Open XML File Format Converter for Mac
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2

Impact

System compromise: Arbitrary code execution.

Recommended Actions

Apply patch, available from the web site.
http://www.microsoft.com/technet/security/Bulletin/MS11-036.mspx

CVE References

CVE-2011-1269