← Vulnerability feed

Vulnerability record · CVE-2010-0033 · published 10 February 2010

CVE-2010-0033: Microsoft PowerPoint 2003 stack buffer overflow via crafted document

Microsoft · Powerpoint

Microsoft Office PowerPoint 2003 SP3 contains a stack-based buffer overflow in its handling of a crafted PowerPoint document, specifically in the TextBytesAtom record. Opening a malicious file can corrupt the stack and allow remote code execution in the context of the user. The flaw is remotely reachable and requires the victim to open the document, making it a classic document-based client-side attack.

9.3 CVSS 2.0 High EPSS 51% · top 1.1% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote code execution with complete impact and a high EPSS score, though exploitation requires user interaction and the affected product is a long-unsupported Office version.

What it is

Microsoft Office PowerPoint 2003 SP3 contains a stack-based buffer overflow in its handling of a crafted PowerPoint document, specifically in the TextBytesAtom record. Opening a malicious file can corrupt the stack and allow remote code execution in the context of the user. The flaw is remotely reachable and requires the victim to open the document, making it a classic document-based client-side attack.

Impact

An attacker who gets a victim to open a crafted PowerPoint file can execute arbitrary code with the privileges of the logged-on user, leading to full compromise of confidentiality, integrity and availability on that host.

Attack surface

Reached over the network via a malicious PowerPoint document delivered by email, web download or file share; no authentication is required, but user interaction (opening the file) is needed, consistent with the AV:N/AC:M/Au:N vector.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated predicted exploitation likelihood; reference tags are limited to a US Government advisory and vendor/OVAL entries, with no public exploit tag.

What to do

  • Apply Microsoft security bulletin MS10-004 for PowerPoint 2003 SP3, or upgrade to a supported Office release.
  • Block or strip untrusted PowerPoint attachments at the mail gateway and restrict document downloads from untrusted sources.
  • Open Office documents with Protected View or equivalent sandboxing where available, and disable automatic opening of embedded objects.
  • Run Office under a low-privilege account and apply application allowlisting to limit post-exploitation execution.

Detection

  • Monitor for PowerPoint 2003 processes spawning child processes such as cmd.exe, powershell.exe or script hosts.
  • Alert on Office applications loading documents from email attachment or temporary internet directories.
  • Hunt for crash or exception events in POWERPNT.EXE correlated with recently opened .ppt files.
  • Review endpoint telemetry for anomalous file writes or network connections originating from Office processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-0033 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2009-0556Microsoft PowerPoint memory corruption via malformed OutlineTextRefAtomMicrosoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac mishandle an OutlineTextRefAtom with an invalid index value,…KEVEPSS 67%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed7.8CVE-2010-2572Microsoft PowerPoint buffer overflow via crafted PowerPoint 95 fileMicrosoft PowerPoint 2002 SP3 and 2003 SP3 contain a buffer overflow when parsing a crafted PowerPoint 95 document. Opening the malicious file can co…KEVEPSS 59%analysed9.3CVE-2015-2503Microsoft access permissions and access controls vulnerabilityMicrosoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007…EPSS 17%9.3CVE-2015-1682Microsoft excel memory buffer overflow vulnerabilityMicrosoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, O…EPSS 19%9.3CVE-2015-0097Microsoft excel vulnerabilityMicrosoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execut…EPSS 41%9.3CVE-2015-0085Microsoft excel vulnerabilityUse-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, Power…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2010-0033), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.