CVE-2015-1649: Use After Free
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1649?
CVE-2015-1649 is classified as critical due to its potential to allow remote code execution.
How do I fix CVE-2015-1649?
To mitigate CVE-2015-1649, users must apply the latest security updates provided by Microsoft.
Which versions of Microsoft Office are affected by CVE-2015-1649?
CVE-2015-1649 affects Microsoft Word 2007 SP3, Office 2010 SP2, and several other related Microsoft products.
Can CVE-2015-1649 be exploited remotely?
Yes, CVE-2015-1649 can be exploited by remote attackers through crafted Office documents.
What type of vulnerability is CVE-2015-1649?
CVE-2015-1649 is a use-after-free vulnerability that can lead to arbitrary code execution.