Lucene search

K
kasperskyKaspersky LabKLA10590
HistoryMar 10, 2015 - 12:00 a.m.

KLA10590 Multiple vulnerabilities in Microsoft Office

2015-03-1000:00:00
Kaspersky Lab
threats.kaspersky.com
20

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.955

Percentile

99.4%

An unspecified vulnerabilities were found in Microsoft Office. By exploiting these vulnerabilities malicious users can cause denial of service or execute arbitrary code. These vulnerabilities can be exploited remotely via a specially designed Office document.

Original advisories

CVE-2015-0064

CVE-2015-0063

CVE-2015-0065

Exploitation

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

Microsoft-Office

CVE list

CVE-2015-0064 critical

CVE-2015-0063 critical

CVE-2015-0065 critical

KB list

2956099

2956073

2956066

2956092

2956058

2956098

2920753

2956081

2920810

2956097

3032328

2920791

2956070

2920788

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Microsoft Office 2007 Service Pack 3Microsoft Office 2010 x86, x64 Service Pack 2Microsoft Office 2013 x86, x64Microsoft Office 2013 x86, x64 Service Pack 1Microsoft Office 2013 x86, x64 RT

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.955

Percentile

99.4%