PT-2015-5734 · Microsoft · Office Compatibility Pack+5
Publicado
2015-07-14
·
Atualizado
2018-10-12
·
CVE-2015-2378
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel 2007 SP3
Microsoft Excel 2010 SP2
Microsoft Excel Viewer 2007 SP3
Microsoft Office Compatibility Pack SP3
Description
A remote code execution issue exists due to improper handling of dynamic link library (DLL) files by Microsoft Excel. This allows an attacker to gain complete control of an affected system by placing a specially crafted DLL file in the target user's current working directory and convincing the user to launch a program that loads the malicious DLL. The attacker could then install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Microsoft Excel 2007 SP3, update to a version that properly handles DLL loading to prevent exploitation.
For Microsoft Excel 2010 SP2, update to a version that properly handles DLL loading to prevent exploitation.
For Microsoft Excel Viewer 2007 SP3, update to a version that properly handles DLL loading to prevent exploitation.
For Microsoft Office Compatibility Pack SP3, update to a version that properly handles DLL loading to prevent exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Excel 2007
Excel 2010
Excel Viewer 2007
Office Compatibility Pack
Office
Office Excel