PT-2015-2326 · Microsoft · Sharepoint Server+3

Published

2015-10-13

·

Updated

2018-10-12

·

CVE-2015-2555

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Excel versions 2010 SP2 through 2016 Microsoft Excel for Mac versions 2011 through 2016 Microsoft SharePoint Server versions 2010 SP2 through 2013 SP1
Description The issue is related to a use-after-free vulnerability in Microsoft Office software, specifically in the handling of objects in memory. This can be exploited by an attacker to execute arbitrary code via a crafted calculatedColumnFormula object in an Office document. The exploitation requires a user to open a specially crafted file with an affected version of Microsoft Office software. If successfully exploited, an attacker could run arbitrary code in the context of the current user, potentially taking control of the affected system if the user has administrative rights.
Recommendations For Microsoft Excel versions 2010 SP2 through 2016, update to a version that properly handles objects in memory to prevent exploitation. For Microsoft Excel for Mac versions 2011 through 2016, update to a version that properly handles objects in memory to prevent exploitation. For Microsoft SharePoint Server versions 2010 SP2 through 2013 SP1, update to a version that properly handles objects in memory to prevent exploitation. As a temporary workaround, consider avoiding the use of the calculatedColumnFormula object in Office documents until a patch is available.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11691
CVE-2015-2555
ZDI-15-517

Affected Products

Office Excel
Excel For Mac
Office
Sharepoint Server