PT-2015-4457 · Microsoft · Excel Viewer+30

Published

2015-03-10

·

Updated

2018-10-12

·

CVE-2015-0085

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office 2007 SP3 Microsoft Excel 2007 SP3 Microsoft PowerPoint 2007 SP3 Microsoft Word 2007 SP3 Microsoft Office 2010 SP2 Microsoft Excel 2010 SP2 Microsoft PowerPoint 2010 SP2 Microsoft Word 2010 SP2 Microsoft Office 2013 Gold and SP1 Microsoft Word 2013 Gold and SP1 Microsoft Office 2013 RT Gold and SP1 Microsoft Word 2013 RT Gold and SP1 Microsoft Excel Viewer Microsoft Office Compatibility Pack SP3 Microsoft Word Automation Services on SharePoint Server 2010 SP2 Microsoft Excel Services on SharePoint Server 2013 Gold and SP1 Microsoft Word Automation Services on SharePoint Server 2013 Gold and SP1 Microsoft Web Applications 2010 SP2 Microsoft Office Web Apps Server 2010 SP2 Microsoft Web Apps Server 2013 Gold and SP1 Microsoft SharePoint Server 2007 SP3 Microsoft Windows SharePoint Services 3.0 SP3 Microsoft SharePoint Foundation 2010 SP2 Microsoft SharePoint Server 2010 SP2 Microsoft SharePoint Foundation 2013 Gold and SP1 Microsoft SharePoint Server 2013 Gold and SP1
Description A remote code execution vulnerability exists in Microsoft Office software due to improper handling of objects in memory while parsing specially crafted Office files. This could corrupt system memory, allowing an attacker to execute arbitrary code. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system, install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of this vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-0085
ZDI-15-088

Affected Products

Excel 2007
Excel 2010
Excel Services
Excel Viewer
Office 2007
Office 2010
Office 2013
Office 2013 Rt
Office Compatibility Pack
Office Web Apps Server 2010
Powerpoint 2007
Powerpoint 2010
Sharepoint Foundation 2010
Sharepoint Foundation 2013
Sharepoint Server 2007
Sharepoint Server 2010
Sharepoint Server 2013
Web Applications 2010
Web Apps Server 2013
Windows Sharepoint Services 3.0
Word 2007
Word 2010
Word 2013
Word 2013 Rt
Word Automation Services
Office
Office Excel
Office Powerpoint
Office Word
Sharepoint Foundation
Sharepoint Server