Lucene search

K
cve[email protected]CVE-2015-1682
HistoryMay 13, 2015 - 10:59 a.m.

CVE-2015-1682

2015-05-1310:59:13
CWE-119
web.nvd.nist.gov
35
cve-2015-1682
microsoft office
excel
powerpoint
word
sharepoint
sharepoint server
memory corruption vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.894 High

EPSS

Percentile

98.8%

Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Office 2013 RT SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office for Mac 2011, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, PowerPoint Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Excel Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, Excel Web App 2010 SP2, Office Web Apps Server 2013 SP1, SharePoint Foundation 2010 SP2, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka “Microsoft Office Memory Corruption Vulnerability.”

Affected configurations

NVD
Node
microsoftexcelMatch2010sp2x64
OR
microsoftexcelMatch2010sp2x86
OR
microsoftexcelMatch2013sp1rt
OR
microsoftexcel_web_appMatch2010sp2
OR
microsoftofficeMatch2010sp2x64
OR
microsoftofficeMatch2010sp2x86
OR
microsoftofficeMatch2011mac
OR
microsoftofficeMatch2013sp1
OR
microsoftofficeMatch2013sp1rt
OR
microsoftoffice_web_apps_serverMatch2010sp2
OR
microsoftoffice_web_apps_serverMatch2013sp1
OR
microsoftpowerpointMatch2010sp2
OR
microsoftpowerpointMatch2011mac
OR
microsoftpowerpointMatch2013sp1
OR
microsoftpowerpointMatch2013sp1rt
OR
microsoftpowerpoint_viewerMatch-
OR
microsoftsharepoint_foundationMatch2010sp2
OR
microsoftsharepoint_foundationMatch2013sp1
OR
microsoftsharepoint_serverMatch2010sp2
OR
microsoftsharepoint_serverMatch2013sp1
OR
microsoftwordMatch2010sp2
OR
microsoftwordMatch2011mac
OR
microsoftwordMatch2013sp1
OR
microsoftwordMatch2013sp1rt

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.894 High

EPSS

Percentile

98.8%