Microsoft PowerPoint Invalid TimeColorBehaviorContainer Record Code Execution Exploit

Microsoft Powerpoint parses a record associated with animation. If a container holds a specific record type, the application will explicitly trust a length used in this record to calculate a pointer for copying floating point numbers to. This can be used to write outside of an allocated buffer and will lead to code execution under the context of the application. WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation.
Exploit type: 
Platform: 
Vulnerabilty ID: 
CVE-2011-0655
Product Version: 
11.0
Released Date: 
Monday, April 18, 2011 - 00:00