CVE-2015-1651: Use After Free
Published Apr 14, 2015
·Updated
Use-after-free vulnerability in Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
Affected Software
3 affected components
Microsoft Office Compatibility Pack=sp3
Microsoft Word=2007-sp3
Microsoft Word Viewer
Event History
Apr 14, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1651?
CVE-2015-1651 has a critical severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2015-1651?
To fix CVE-2015-1651, you should apply the security updates provided by Microsoft for Word 2007 SP3 and related products.
3
What products are affected by CVE-2015-1651?
CVE-2015-1651 affects Microsoft Word 2007 SP3, Microsoft Word Viewer, and the Office Compatibility Pack SP3.
4
What type of vulnerability is CVE-2015-1651?
CVE-2015-1651 is a use-after-free vulnerability.
5
Can CVE-2015-1651 be exploited through email attachments?
Yes, CVE-2015-1651 can be exploited through crafted Office documents, often delivered via email attachments.