CVE-2006-0004
Description
Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Microsoft PowerPoint 2000 in Office 2000 SP3 can disclose sensitive data from the Temporary Internet Files Folder via crafted presentations.
Vulnerability
Microsoft PowerPoint 2000 running on Office 2000 Service Pack 3 contains an information disclosure vulnerability (CVE-2006-0004). The bug is triggered when PowerPoint attempts to render HTML in a presentation, failing to properly restrict access to objects in the Temporary Internet Files Folder (TIFF) [1][3]. This affects only PowerPoint 2000; Office XP, Office 2003, and PowerPoint 2002/2003 are not vulnerable [1].
Exploitation
An attacker must craft a malicious PowerPoint presentation that references specific objects by name in the victim's Temporary Internet Files Folder. The victim must open the presentation in PowerPoint 2000. No special network position or authentication is required beyond convincing the user to open the file [1][2][3]. The attacker needs prior knowledge of the exact filenames of objects within the TIFF directory [3].
Impact
Successful exploitation results in information disclosure: the attacker can remotely read the contents of files in the victim's Temporary Internet Files Folder, which may contain sensitive data such as cached credentials, session tokens, or other private information. This vulnerability does not allow code execution or direct privilege escalation [1][3].
Mitigation
Microsoft released security update MS06-010 on February 14, 2006, which addresses the vulnerability for PowerPoint 2000 [1]. The update is available for download; customers should apply it at the earliest opportunity. System administrators can also restrict opening of PowerPoint files from untrusted sources as a workaround [1][3].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: =2000
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.kb.cert.org/vuls/id/963628nvdUS Government Resource
- secunia.com/advisories/18865nvd
- securitytracker.com/idnvd
- www.securityfocus.com/bid/16634nvd
- www.vupen.com/english/advisories/2006/0579nvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-010nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24490nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1555nvd
News mentions
0No linked articles in our index yet.