PT-2015-5424 · Microsoft · Excel Services+29

Published

2015-05-12

·

Updated

2018-10-12

·

CVE-2015-1682

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office 2010 SP2 Excel 2010 SP2 PowerPoint 2010 SP2 Word 2010 SP2 Office 2013 SP1 Excel 2013 SP1 PowerPoint 2013 SP1 Word 2013 SP1 Office 2013 RT SP1 Excel 2013 RT SP1 PowerPoint 2013 RT SP1 Word 2013 RT SP1 Office for Mac 2011 Excel for Mac 2011 PowerPoint for Mac 2011 Word for Mac 2011 PowerPoint Viewer Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1 Excel Services on SharePoint Server 2010 SP2 and 2013 SP1 Office Web Apps 2010 SP2 Excel Web App 2010 SP2 Office Web Apps Server 2013 SP1 SharePoint Foundation 2010 SP2 SharePoint Server 2013 SP1
Description Remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. Exploitation of these vulnerabilities requires that a user open a specially crafted file with an affected version of Microsoft Office software. An attacker who successfully exploited these vulnerabilities could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1682
ZDI-15-182

Affected Products

Excel 2010
Excel 2013
Excel 2013 Rt
Excel Services
Excel Web App 2010
Excel For Mac 2011
Office 2010
Office
Office 2013
Office 2013 Rt
Office Excel
Office Powerpoint
Office Web Apps 2010
Office Web Apps Server 2013
Office Word
Office For Mac 2011
Powerpoint 2010
Powerpoint 2013 Rt
Powerpoint Viewer
Powerpoint For Mac 2011
Sharepoint Foundation 2010
Sharepoint Server 2010
Sharepoint Server 2013
Sharepoint Foundation
Sharepoint Server
Word 2010
Word 2013
Word 2013 Rt
Word Automation Services
Word For Mac 2011