First published: Tue Apr 14 2015(Updated: )
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | ||
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Web Apps | =2010-sp2 | |
Microsoft Office Web Apps | =2013-sp1 | |
Microsoft SharePoint Server 2010 | =2010-sp2 | |
Microsoft SharePoint Server 2010 | =2013-sp1 | |
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2010-sp2 | |
Microsoft Office Word | =2011 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Outlook for Mac | =2011 | |
Microsoft Word for Mac | =2011 | |
Microsoft Office Word | =2013-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1641 has a critical severity rating, allowing remote attackers to execute arbitrary code on affected systems.
To fix CVE-2015-1641, apply the latest security updates provided by Microsoft for the affected versions of Word and Office applications.
CVE-2015-1641 affects Microsoft Word 2007, 2010, 2013, the Office Compatibility Pack, and several Office Web Apps and SharePoint Server versions.
CVE-2015-1641 could allow attackers to gain control over a system by exploiting the vulnerability through specially crafted documents.
Yes, CVE-2015-1641 affects Microsoft Word for Mac 2011, making it vulnerable to the same exploitation risks.