PowerPoint binary-format RCE payload — CVE-2011-1269 / MS11-036 family

PPT_BINARY_MEMORY_CORRUPTION_PAYLOAD

← All detection heuristics · Office

critical CVE related PPT_BINARY_MEMORY_CORRUPTION_PAYLOAD

What it means

Macro-free binary PowerPoint carries a native code payload (embedded PE / process-injection shellcode).

Why it fires

A binary PowerPoint 97-2003 (.ppt) document with no VBA macros that carries an embedded PE and/or process-injection shellcode (PEB+API-hash resolver, WriteProcessMemory/CreateRemoteThread), or an XOR-encoded payload alongside execution-API strings, staged in an oversized binary stream (Pictures, a numbered *Table). Legitimate presentations never embed executables or shellcode; this is the payload half of a PowerPoint memory-corruption exploit. Attributed to the CVE-2011-1269 / MS11-036 family (the same record-overflow delivery is shared with CVE-2010-2572 and CVE-2009-0556, so the exact CVE is not narrowed statically). The malformed-record trigger itself is not used as the signal because the PowerPoint persist-object directory makes naive record walks unreliable.

Other Office heuristics

OLE_VBA_AFFINE_MSI_DOWNLOADER OLE_VBA_AUTOEXEC_FRAGMENTED_SHELL OLE_VBA_DESTRUCTIVE_WORKBOOK_SHUTDOWN OLE_VBA_BIDIRECTIONAL_MACROCOPY_REPLICATION OOXML_BRAND_LINK_MISMATCH_LURE CVE_2016_7262 POLYGLOT_OOXML_REL_COMMAND OLE_RAW_PCODE_CROSS_DOCUMENT_REPLICATION OLE_VBA_CROSS_WORKBOOK_REPLICATION OOXML_XLM_DANGEROUS_FN OFFICE_DEFAULT_PASSWORD_VBA_DROP_EXEC OFFICE_EMBEDDED_SWF EMBEDDED_OFFICE_CHILD_STATIC_TRIAGE OFFICE_EMBEDDED_MACRO_OBJECT OLE_EMBEDDED_EXE OLE_VBA_EMBEDDED_PE_DROPPER OLE_ENCRYPTED_AND_MALFORMED CVE_2017_11882_EQUATION_NATIVE_CMD_RELATED CVE_2017_11882 OLE_EQUATION_OLE10NATIVE_DOWNLOADER OLE_MTEF_NATIVE_CODE_STUB OLE_EQUATION_OLE10NATIVE_SHELLCODE OOXML_XLM_MACRO_IN_WORKSHEET OLE_XLS5_LAROUX_MACRO_VIRUS