PT-2015-5734 · Microsoft · Office Compatibility Pack+5

Publicado

2015-07-14

·

Atualizado

2018-10-12

·

CVE-2015-2378

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Excel 2007 SP3 Microsoft Excel 2010 SP2 Microsoft Excel Viewer 2007 SP3 Microsoft Office Compatibility Pack SP3
Description A remote code execution issue exists due to improper handling of dynamic link library (DLL) files by Microsoft Excel. This allows an attacker to gain complete control of an affected system by placing a specially crafted DLL file in the target user's current working directory and convincing the user to launch a program that loads the malicious DLL. The attacker could then install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Excel 2007 SP3, update to a version that properly handles DLL loading to prevent exploitation. For Microsoft Excel 2010 SP2, update to a version that properly handles DLL loading to prevent exploitation. For Microsoft Excel Viewer 2007 SP3, update to a version that properly handles DLL loading to prevent exploitation. For Microsoft Office Compatibility Pack SP3, update to a version that properly handles DLL loading to prevent exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2015-2378

Produtos afetados

Excel 2007
Excel 2010
Excel Viewer 2007
Office Compatibility Pack
Office
Office Excel