Lucene search

K
cveMicrosoftCVE-2015-2520
HistorySep 09, 2015 - 12:59 a.m.

CVE-2015-2520

2015-09-0900:59:32
CWE-119
microsoft
web.nvd.nist.gov
65
cve-2015-2520
microsoft excel
remote code execution
office document
memory corruption
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.957

Percentile

99.4%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka “Microsoft Office Memory Corruption Vulnerability.”

Affected configurations

Nvd
Node
microsoftexcelMatch2007sp3
OR
microsoftexcelMatch2010sp2x64
OR
microsoftexcelMatch2010sp2x86
OR
microsoftexcelMatch2011mac
OR
microsoftexcelMatch2013sp1
OR
microsoftexcelMatch2013sp1rt
OR
microsoftexcelMatch2016mac
OR
microsoftexcel_viewer
OR
microsoftoffice_compatibility_packsp3
VendorProductVersionCPE
microsoftexcel2007cpe:2.3:a:microsoft:excel:2007:sp3:*:*:*:*:*:*
microsoftexcel2010cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:x64:*
microsoftexcel2010cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:x86:*
microsoftexcel2011cpe:2.3:a:microsoft:excel:2011:*:*:*:*:mac:*:*
microsoftexcel2013cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:*
microsoftexcel2013cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:*
microsoftexcel2016cpe:2.3:a:microsoft:excel:2016:*:*:*:*:mac:*:*
microsoftexcel_viewer*cpe:2.3:a:microsoft:excel_viewer:*:*:*:*:*:*:*:*
microsoftoffice_compatibility_pack*cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.957

Percentile

99.4%