PT-2015-4457 · Microsoft · Excel Viewer+30
Published
2015-03-10
·
Updated
2018-10-12
·
CVE-2015-0085
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2007 SP3
Microsoft Excel 2007 SP3
Microsoft PowerPoint 2007 SP3
Microsoft Word 2007 SP3
Microsoft Office 2010 SP2
Microsoft Excel 2010 SP2
Microsoft PowerPoint 2010 SP2
Microsoft Word 2010 SP2
Microsoft Office 2013 Gold and SP1
Microsoft Word 2013 Gold and SP1
Microsoft Office 2013 RT Gold and SP1
Microsoft Word 2013 RT Gold and SP1
Microsoft Excel Viewer
Microsoft Office Compatibility Pack SP3
Microsoft Word Automation Services on SharePoint Server 2010 SP2
Microsoft Excel Services on SharePoint Server 2013 Gold and SP1
Microsoft Word Automation Services on SharePoint Server 2013 Gold and SP1
Microsoft Web Applications 2010 SP2
Microsoft Office Web Apps Server 2010 SP2
Microsoft Web Apps Server 2013 Gold and SP1
Microsoft SharePoint Server 2007 SP3
Microsoft Windows SharePoint Services 3.0 SP3
Microsoft SharePoint Foundation 2010 SP2
Microsoft SharePoint Server 2010 SP2
Microsoft SharePoint Foundation 2013 Gold and SP1
Microsoft SharePoint Server 2013 Gold and SP1
Description
A remote code execution vulnerability exists in Microsoft Office software due to improper handling of objects in memory while parsing specially crafted Office files. This could corrupt system memory, allowing an attacker to execute arbitrary code. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system, install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of this vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Excel 2007
Excel 2010
Excel Services
Excel Viewer
Office 2007
Office 2010
Office 2013
Office 2013 Rt
Office Compatibility Pack
Office Web Apps Server 2010
Powerpoint 2007
Powerpoint 2010
Sharepoint Foundation 2010
Sharepoint Foundation 2013
Sharepoint Server 2007
Sharepoint Server 2010
Sharepoint Server 2013
Web Applications 2010
Web Apps Server 2013
Windows Sharepoint Services 3.0
Word 2007
Word 2010
Word 2013
Word 2013 Rt
Word Automation Services
Office
Office Excel
Office Powerpoint
Office Word
Sharepoint Foundation
Sharepoint Server