Lucene search

K
nvd[email protected]NVD:CVE-2015-2470
HistoryAug 15, 2015 - 12:59 a.m.

CVE-2015-2470

2015-08-1500:59:29
CWE-189
web.nvd.nist.gov
1

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.578

Percentile

97.7%

Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 2011, and Word Viewer allows remote attackers to execute arbitrary code via a crafted document, aka “Microsoft Office Integer Underflow Vulnerability.”

Affected configurations

NVD
Node
microsoftofficeMatch2010sp2x64
OR
microsoftofficeMatch2010sp2x86
OR
microsoftofficeMatch2011mac
OR
microsoftofficeMatch2013sp1
OR
microsoftwordMatch2007sp3
OR
microsoftword_viewer

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.578

Percentile

97.7%