Cisco Event Response: Microsoft Security Bulletin Release for May 2009

May 12, 2009

Microsoft published its monthly security bulletin release on May 12, 2009. One bulletin was released that addresses 14 individual vulnerabilities. Microsoft has scored the bulletin with a maximum severity rating of Critical.  This bulletin addresses vulnerabilities in the Microsoft Office PowerPoint software. In every case, a successful exploit requires a user to open a malformed PowerPoint file; an attacker cannot force a user to do so directly. One vulnerability, which is described in CVE-2009-0556 and IntelliShield alert 17966, is being actively exploited in the wild.


Event Intelligence

The following table identifies Cisco Security Intelligence Operations content and Cisco mitigation information that is associated with this Microsoft release:

Microsoft Security Bulletin Cisco IntelliShield Alert
CVE ID
Search CVEs
Cisco Mitigations
CVSS
Base Score
CVSS Q&A

Microsoft Security Bulletin MS09-017

Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution

Microsoft Office PowerPoint Legacy File Format Processing Arbitrary Code Execution Vulnerability
CVE-2009-0220

Cisco IPS Signature 17127-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Integer Overflow Vulnerability
CVE-2009-0221

Cisco IPS Signature 16958-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Legacy File Processing Memory Corruption Vulnerability
CVE-2009-0222

Cisco IPS Signature 17077-2

Cisco Security MARS

9.3
Microsoft Office PowerPoint Legacy File Sound Object Processing Vulnerability
CVE-2009-0223

Cisco IPS Signature 17077-1

Cisco Security MARS

9.3
Microsoft Office PowerPoint Invalid Record Processing Arbitrary Code Execution Vulnerability
CVE-2009-0224

Cisco IPS Signature 16977-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Sound Data Processing Arbitrary Code Execution Vulnerability
CVE-2009-0225

Cisco IPS Signature 17153-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Legacy File Processing Memory Corruption Vulnerability
CVE-2009-0226

Cisco IPS Signature 17146-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Legacy Document Type Sound Processing Vulnerability
CVE-2009-0227

Cisco IPS Signature 17155-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Arbitrary Code Execution Vulnerability
CVE-2009-0556

Cisco IPS Signature 16333-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Legacy Sound Data Memory Corruption Vulnerability
CVE-2009-1128

Cisco IPS Signature 17077-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Legacy File Handling Memory Corruption Vulnerability
CVE-2009-1129

Cisco IPS Signature 16933-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Structure Processing Heap Corruption Vulnerability
CVE-2009-1130

Cisco IPS Signature 16956-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Data Out of Bounds Memory Corruption Vulnerability
CVE-2009-1131

Cisco IPS Signature 16957-0

Cisco Security MARS

9.3
Microsoft Office PowerPoint Legacy File Sound Data Processing Memory Corruption Vulnerability
CVE-2009-1137

Cisco IPS Signature 17152-0

Cisco Security MARS

9.3


Cisco Security Intelligence Operations

Cisco Applied Mitigation Bulletins provide identification and mitigation techniques that administrators can deploy on Cisco network devices. Cisco Intrusion Prevention System (IPS) signatures and Cisco Security Monitoring, Analysis, and Response System Incidents are discussed in this bulletin.

Cisco Applied Mitigation Bulletin: Microsoft Security Bulletin Release for May 2009


Impact on Cisco Products

Impact Assessment of May 2009 Microsoft Security Bulletins on Cisco Contact Center and Self Service Products New!
Impact Assessments for Cisco Contact Center and Self Service Products evaluate Microsoft security bulletins and associated software updates for potential impact to Cisco Contact Center products. For each respective Microsoft Security Bulletin, a Microsoft update is assigned one of three categorical ratings: Impacting, Deferred, or Not Applicable.

Cisco IP Telephony Operating System, SQL Server, Security Updates
This document contains information on software updates for tracking Cisco-supported operating system, SQL Server, and security files that are available for web download. These updates support all versions of Cisco Unified CallManager, Cisco Conference Connection, Cisco Personal Assistant, Cisco IP Interactive Voice Response, and Cisco IP Call Center Express, Cisco Emergency Responder, Cisco Customer Voice Portal, and Cisco MeetingPlace. This document does not support Cisco Unity or servers where Cisco Unity is installed.