PT-2015-2326 · Microsoft · Sharepoint Server+3
Published
2015-10-13
·
Updated
2018-10-12
·
CVE-2015-2555
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel versions 2010 SP2 through 2016
Microsoft Excel for Mac versions 2011 through 2016
Microsoft SharePoint Server versions 2010 SP2 through 2013 SP1
Description
The issue is related to a use-after-free vulnerability in Microsoft Office software, specifically in the handling of objects in memory. This can be exploited by an attacker to execute arbitrary code via a crafted
calculatedColumnFormula object in an Office document. The exploitation requires a user to open a specially crafted file with an affected version of Microsoft Office software. If successfully exploited, an attacker could run arbitrary code in the context of the current user, potentially taking control of the affected system if the user has administrative rights.Recommendations
For Microsoft Excel versions 2010 SP2 through 2016, update to a version that properly handles objects in memory to prevent exploitation.
For Microsoft Excel for Mac versions 2011 through 2016, update to a version that properly handles objects in memory to prevent exploitation.
For Microsoft SharePoint Server versions 2010 SP2 through 2013 SP1, update to a version that properly handles objects in memory to prevent exploitation.
As a temporary workaround, consider avoiding the use of the
calculatedColumnFormula object in Office documents until a patch is available.Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Excel
Excel For Mac
Office
Sharepoint Server