PT-2015-5424 · Microsoft · Excel Services+29
Published
2015-05-12
·
Updated
2018-10-12
·
CVE-2015-1682
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2010 SP2
Excel 2010 SP2
PowerPoint 2010 SP2
Word 2010 SP2
Office 2013 SP1
Excel 2013 SP1
PowerPoint 2013 SP1
Word 2013 SP1
Office 2013 RT SP1
Excel 2013 RT SP1
PowerPoint 2013 RT SP1
Word 2013 RT SP1
Office for Mac 2011
Excel for Mac 2011
PowerPoint for Mac 2011
Word for Mac 2011
PowerPoint Viewer
Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1
Excel Services on SharePoint Server 2010 SP2 and 2013 SP1
Office Web Apps 2010 SP2
Excel Web App 2010 SP2
Office Web Apps Server 2013 SP1
SharePoint Foundation 2010 SP2
SharePoint Server 2013 SP1
Description
Remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. Exploitation of these vulnerabilities requires that a user open a specially crafted file with an affected version of Microsoft Office software. An attacker who successfully exploited these vulnerabilities could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Excel 2010
Excel 2013
Excel 2013 Rt
Excel Services
Excel Web App 2010
Excel For Mac 2011
Office 2010
Office
Office 2013
Office 2013 Rt
Office Excel
Office Powerpoint
Office Web Apps 2010
Office Web Apps Server 2013
Office Word
Office For Mac 2011
Powerpoint 2010
Powerpoint 2013 Rt
Powerpoint Viewer
Powerpoint For Mac 2011
Sharepoint Foundation 2010
Sharepoint Server 2010
Sharepoint Server 2013
Sharepoint Foundation
Sharepoint Server
Word 2010
Word 2013
Word 2013 Rt
Word Automation Services
Word For Mac 2011