Lucene search

K
kasperskyKaspersky LabKLA10645
HistoryAug 11, 2015 - 12:00 a.m.

KLA10645 Multiple vulnerabilities in Microsoft Office

2015-08-1100:00:00
Kaspersky Lab
threats.kaspersky.com
90

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

Low

0.941 High

EPSS

Percentile

99.2%

Multiple serious vulnerabilities have been found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code or obtain sensitive information.

Below is a complete list of vulnerabilities

  1. Improper memory objects handling can be exploited remotely via a specially designed file to execute arbitrary code;
  2. An unknown vulnerability can be exploited remotely via a specially designed file to obtain sensitive information.

Technical details

To exploit (2) attacker must first leverage another vulnerability to cause code execution in IE with EPM. Than malicious can execute Excel, Notepad, PowerPoint or another with unsafe command line parameter. Another part of updates for this vulnerability listed in KLA10646, KLA10648

Original advisories

CVE-2015-1642

CVE-2015-2423

CVE-2015-2466

CVE-2015-2468

CVE-2015-2467

CVE-2015-2469

CVE-2015-2470

CVE-2015-2477

Exploitation

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

Microsoft-Office

CVE list

CVE-2015-1642 critical

CVE-2015-2423 warning

CVE-2015-2466 critical

CVE-2015-2468 critical

CVE-2015-2467 critical

CVE-2015-2469 critical

CVE-2015-2470 critical

CVE-2015-2477 critical

KB list

2687409

3054858

3054888

3054960

3039798

3054929

3055039

2965280

3055030

3055054

3055033

3055052

3055053

3055037

3055051

3054876

3054992

3054991

3054816

2965310

3055003

2553313

3054974

3082420

3055044

3080790

3081349

2596650

2986254

2598244

2837610

3039734

3055029

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Office 2007 Service Pack 3Office 2010 Service Pack 2Office 2013 Service Pack 1Office 2013 RT Service Pack 1Office for Mac 2011, 2016Office Compatibility Pack Service Pack 3Word ViewerSharePoint Server 2010 Service Pack 2SharePoint Server 2013 Service Pack 1Word Web Apps 2010 Service Pack 2Office Web Apps Server 2013 Service Pack 1

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

Low

0.941 High

EPSS

Percentile

99.2%