Vulnerability record · CVE-2010-2572 · published 10 November 2010
CVE-2010-2572: Microsoft PowerPoint buffer overflow via crafted PowerPoint 95 file
Microsoft · Powerpoint
Microsoft PowerPoint 2002 SP3 and 2003 SP3 contain a buffer overflow when parsing a crafted PowerPoint 95 document. Opening the malicious file can corrupt memory and allow remote code execution in the context of the user. The flaw is a classic buffer overflow (CWE-120) and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote code execution, is listed in CISA KEV, and has a very high EPSS score, though exploitation requires user interaction and affects only legacy PowerPoint versions.
What it is
Microsoft PowerPoint 2002 SP3 and 2003 SP3 contain a buffer overflow when parsing a crafted PowerPoint 95 document. Opening the malicious file can corrupt memory and allow remote code execution in the context of the user. The flaw is a classic buffer overflow (CWE-120) and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker who gets a victim to open the crafted document can execute arbitrary code with the privileges of the logged-on user, potentially leading to full system compromise.
Attack surface
The vulnerability is reached locally when a user opens a malicious PowerPoint 95 file; the CVSS vector shows AV:L with UI:R and PR:N, so no authentication is required but user interaction (opening the file) is needed.
Exploitation
CVE-2010-2572 is listed in CISA KEV (added 2022-06-08) and has a high EPSS 30-day probability of 0.626 (99th percentile), indicating observed exploitation activity. No ransomware campaign use is documented in the record.
What to do
- Apply the Microsoft security update referenced in MS10-088 (patch first).
- Upgrade or remove unsupported PowerPoint 2002 and 2003 installations.
- Block or quarantine PowerPoint 95 (.ppt) files at email and web gateways where feasible.
- Disable or restrict opening of legacy PowerPoint formats via Group Policy or file association controls.
- Train users not to open unexpected PowerPoint attachments from untrusted sources.
Detection
- Monitor for PowerPoint processes spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Alert on Office applications loading or writing files from unusual paths (temp, user profile, network shares) after opening a document.
- Search endpoint logs for crashes or memory corruption events in POWERPNT.EXE tied to document opens.
- Review email and proxy logs for PowerPoint 95 attachments or downloads matching known exploit indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2010-2572 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Microsoft PowerPoint Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.us-cert.gov/cas/techalerts/TA10-313A.html | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-088 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12195 | Broken Link |
| http://www.us-cert.gov/cas/techalerts/TA10-313A.html | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-088 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12195 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-2572 | US Government Resource |
Track CVE-2010-2572 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2572), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.