First published: Wed Feb 11 2015(Updated: )
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Office Remote Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Web Applications | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Word Automation Services | ||
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2010-sp2 | |
Microsoft Office Word Viewer | ||
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2010-sp2 | |
Microsoft SharePoint Server 2010 | =2010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0064 has a high severity rating due to its potential to allow remote code execution or denial of service.
To fix CVE-2015-0064, apply the latest security patches provided by Microsoft for the affected software.
CVE-2015-0064 affects Microsoft Word 2007 SP3, Office 2010 SP2, Word Automation Services, and several other Microsoft applications.
It is highly discouraged to use affected versions of Microsoft products without applying the necessary updates for CVE-2015-0064.
CVE-2015-0064 can enable attackers to execute arbitrary code or cause a denial of service through crafted Office documents.