[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Use after free in Microsoft Office via a crafted office file - CVE-2015-0085

ID: oval:org.secpod.oval:def:23797Date: (C)2015-03-13   (M)2021-06-02
Class: VULNERABILITYFamily: windows




The host is installed with Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 Gold or SP1, Word 2013 Gold or SP1, Office 2013 RT Gold or SP1, Word 2013 RT Gold or SP1, Excel Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Excel Services on SharePoint Server 2013 Gold or SP1, Word Automation Services on SharePoint Server 2013 Gold or SP1, Web Applications 2010 SP2, Office Web Apps Server 2010 SP2, Web Apps Server 2013 Gold or SP1, SharePoint Server 2007 SP3, Windows SharePoint Services 3.0 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold or SP1 or SharePoint Server 2013 Gold or SP1 and is prone to an use after free vulnerability. A flaw is present in the applications, which fail to handle a crafted file. Successful exploitation could allow attackers to execute arbitrary code.

Platform:
Microsoft Windows Server 2019
Microsoft Windows Server 2016
Microsoft Windows Server 2003
Microsoft Windows 10
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product:
Microsoft Excel 2007
Microsoft Excel 2010
Microsoft Excel Viewer 2007
Microsoft Office 2007
Microsoft Office 2010
Microsoft Office 2013
Microsoft Office Compatibility Pack
Microsoft Office Web Apps 2010
Microsoft Office Web Apps Server 2013
Microsoft PowerPoint 2007
Microsoft PowerPoint 2010
Microsoft SharePoint Foundation 2010
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2007
Microsoft SharePoint Server 2010
Microsoft SharePoint Server 2013
Microsoft SharePoint Services 3.0
Microsoft Word 2007
Microsoft Word 2010
Microsoft Word 2013
Reference:
CVE-2015-0085
CVE    1
CVE-2015-0085
CPE    44
cpe:/a:microsoft:powerpoint:2010:sp2
cpe:/a:microsoft:excel:2010:sp2
cpe:/a:microsoft:word:2007:sp3
cpe:/a:microsoft:office:2010:sp2
...

© SecPod Technologies