CVE-2015-2558
Summary
| CVE | CVE-2015-2558 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-10-14 01:59:13 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Use-after-free vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Excel Viewer, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a long fileVersion element in an Office document, aka "Microsoft Office Memory Corruption Vulnerability." |
Risk And Classification
Primary CVSS: v2.0 9.3 from [email protected]
AV:N/AC:M/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Excel | 2007 | sp3 | All | All |
| Application | Microsoft | Excel | 2010 | sp2 | All | All |
| Application | Microsoft | Excel | 2010 | sp2 | All | All |
| Application | Microsoft | Excel | 2013 | sp1 | All | All |
| Application | Microsoft | Excel | 2013 | sp1 | All | All |
| Application | Microsoft | Excel | 2016 | All | All | All |
| Application | Microsoft | Excel For Mac | 2011 | All | All | All |
| Application | Microsoft | Excel For Mac | 2016 | All | All | All |
| Application | Microsoft | Excel Viewer | All | All | All | All |
| Application | Microsoft | Office Compatibility Pack | All | sp3 | All | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp3 | x32 | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp3 | x64 | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Sharepoint Server | 2013 | sp1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZDI-15-516 | Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| Microsoft Security Bulletin MS15-110 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Microsoft Office Flaws Let Remote Users Execute Arbitrary Code and Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.