PT-2015-5733 · Microsoft · Excel Viewer+3
Publicado
2015-07-14
·
Atualizado
2018-10-12
·
CVE-2015-2375
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel versions 2010 SP2 through 2013 SP1
Excel Viewer version 2007 SP3
Excel Services on SharePoint Server versions 2010 SP2 through 2013 SP1
Description
A security feature bypass issue exists in Microsoft Excel, allowing remote attackers to bypass the Address Space Layout Randomization (ASLR) protection mechanism. This could potentially allow remote code execution when used in conjunction with another vulnerability, such as a remote code execution vulnerability. The issue arises when memory is released in an unintended manner, and exploitation requires a user to open a specially crafted Excel file with an affected version of Microsoft Office software.
Recommendations
For Microsoft Excel versions 2010 SP2 through 2013 SP1, update to a version that includes the fix for this issue.
For Excel Viewer version 2007 SP3, update to a version that includes the fix for this issue.
For Excel Services on SharePoint Server versions 2010 SP2 through 2013 SP1, update to a version that includes the fix for this issue.
As a temporary workaround, consider avoiding the use of
Excel table Tag functionality until a patch is available.
Restrict access to specially crafted Excel files to minimize the risk of exploitation.Correção
RCE
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Excel Services
Excel Viewer
Office Excel
Sharepoint Server