Microsoft Office CVE-2015-0086 Memory Corruption Vulnerability
BID:72911
Info
Microsoft Office CVE-2015-0086 Memory Corruption Vulnerability
| Bugtraq ID: | 72911 |
| Class: | Unknown |
| CVE: |
CVE-2015-0086 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2015 12:00AM |
| Updated: | Mar 10 2015 12:00AM |
| Credit: | Ben Hawkes of the Google Security Team. |
| Vulnerable: |
Microsoft Word Automation Services on Microsoft SharePoint Server 2013 Service Pack 1 Microsoft Word Automation Services on Microsoft SharePoint Server 2013 0 Microsoft Word Automation Services on Microsoft SharePoint Server 2010 SP2 0 Microsoft Word 2013 Service Pack 1 (64-bit editions) Microsoft Word 2013 Service Pack 1 (32-bit editions) Microsoft Word 2013 RT Service Pack 1 0 Microsoft Word 2013 RT 0 Microsoft Word 2013 (64-bit editions) 0 Microsoft Word 2013 (32-bit editions) 0 Microsoft Word 2010 Service Pack 2 (64-bit editions) 0 Microsoft Word 2010 Service Pack 2 (32-bit editions) 0 Microsoft Word 2007 SP3 Microsoft Web Apps Server 2013 Service Pack 1 Microsoft Web Applications 2010 Service Pack 2 Microsoft Office Word Viewer 0 Microsoft Office Web Apps Server 2013 0 Microsoft Office Compatibility Pack Service Pack 3 0 Microsoft Office 2010 (64-bit edition) SP2 Microsoft Office 2010 (32-bit edition) SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Office CVE-2015-0086 Memory Corruption Vulnerability
Microsoft Office is prone to a memory-corruption vulnerability because it fails to properly handle rich text format files in memory.
An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
Microsoft Office is prone to a memory-corruption vulnerability because it fails to properly handle rich text format files in memory.
An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
References
Microsoft Office CVE-2015-0086 Memory Corruption Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Office Product Homepage (Microsoft)
- Microsoft Security Bulletin MS15-022 (Microsoft)