Lucene search

K
cve[email protected]CVE-2015-6124
HistoryDec 09, 2015 - 11:59 a.m.

CVE-2015-6124

2015-12-0911:59:09
CWE-119
web.nvd.nist.gov
32
cve-2015-6124
microsoft
word
office
memory corruption
vulnerability
remote execution

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.17 Low

EPSS

Percentile

96.1%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka “Microsoft Office Memory Corruption Vulnerability.”

Affected configurations

NVD
Node
microsoftofficeMatch2010sp2x64
OR
microsoftofficeMatch2010sp2x86
OR
microsoftofficeMatch2013sp1
OR
microsoftoffice_compatibility_packsp3
OR
microsoftwordMatch2007sp3

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.17 Low

EPSS

Percentile

96.1%