Lucene search

K
cve[email protected]CVE-2015-2376
HistoryJul 14, 2015 - 9:59 p.m.

CVE-2015-2376

2015-07-1421:59:11
CWE-119
web.nvd.nist.gov
39
cve-2015-2376
microsoft excel
office for mac
excel viewer
office compatibility pack
sharepoint
remote code execution
memory corruption
vulnerability
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.772 High

EPSS

Percentile

98.2%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Office for Mac 2011, Excel Viewer 2007 SP3, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka “Microsoft Office Memory Corruption Vulnerability.”

Affected configurations

NVD
Node
microsoftexcelMatch2007sp3
OR
microsoftexcelMatch2010sp2x64
OR
microsoftexcelMatch2010sp2x86
OR
microsoftexcelMatch2013sp1
OR
microsoftexcelMatch2013sp1rt
OR
microsoftexcel_viewerMatch2007sp3
OR
microsoftofficeMatch2011mac
OR
microsoftoffice_compatibility_packsp3
OR
microsoftsharepoint_designerMatch2007sp3
OR
microsoftsharepoint_designerMatch2010sp2
OR
microsoftsharepoint_designerMatch2013sp1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.772 High

EPSS

Percentile

98.2%