Vulnerability record · CVE-2010-0033 · published 10 February 2010
CVE-2010-0033: Microsoft PowerPoint 2003 stack buffer overflow via crafted document
Microsoft · Powerpoint
Microsoft Office PowerPoint 2003 SP3 contains a stack-based buffer overflow in its handling of a crafted PowerPoint document, specifically in the TextBytesAtom record. Opening a malicious file can corrupt the stack and allow remote code execution in the context of the user. The flaw is remotely reachable and requires the victim to open the document, making it a classic document-based client-side attack.
Description
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with complete impact and a high EPSS score, though exploitation requires user interaction and the affected product is a long-unsupported Office version.
What it is
Microsoft Office PowerPoint 2003 SP3 contains a stack-based buffer overflow in its handling of a crafted PowerPoint document, specifically in the TextBytesAtom record. Opening a malicious file can corrupt the stack and allow remote code execution in the context of the user. The flaw is remotely reachable and requires the victim to open the document, making it a classic document-based client-side attack.
Impact
An attacker who gets a victim to open a crafted PowerPoint file can execute arbitrary code with the privileges of the logged-on user, leading to full compromise of confidentiality, integrity and availability on that host.
Attack surface
Reached over the network via a malicious PowerPoint document delivered by email, web download or file share; no authentication is required, but user interaction (opening the file) is needed, consistent with the AV:N/AC:M/Au:N vector.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated predicted exploitation likelihood; reference tags are limited to a US Government advisory and vendor/OVAL entries, with no public exploit tag.
What to do
- Apply Microsoft security bulletin MS10-004 for PowerPoint 2003 SP3, or upgrade to a supported Office release.
- Block or strip untrusted PowerPoint attachments at the mail gateway and restrict document downloads from untrusted sources.
- Open Office documents with Protected View or equivalent sandboxing where available, and disable automatic opening of embedded objects.
- Run Office under a low-privilege account and apply application allowlisting to limit post-exploitation execution.
Detection
- Monitor for PowerPoint 2003 processes spawning child processes such as cmd.exe, powershell.exe or script hosts.
- Alert on Office applications loading documents from email attachment or temporary internet directories.
- Hunt for crash or exception events in POWERPNT.EXE correlated with recently opened .ppt files.
- Review endpoint telemetry for anomalous file writes or network connections originating from Office processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0033 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0033), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.