First published: Tue Jul 14 2015(Updated: )
Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to bypass the ASLR protection mechanism via a crafted spreadsheet, aka "Microsoft Excel ASLR Bypass Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft SharePoint Server 2010 | =2010-sp2 | |
Microsoft SharePoint Server 2010 | =2013-sp1 | |
Microsoft Office Excel Viewer | =2007-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2375 has been classified as important in terms of severity due to its potential for exploitation.
To mitigate CVE-2015-2375, it is recommended to apply the relevant Microsoft security updates available for the affected software versions.
CVE-2015-2375 affects Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel Viewer 2007 SP3, and SharePoint Server 2010 SP2/2013 SP1.
Yes, CVE-2015-2375 can be exploited by remote attackers through a specially crafted spreadsheet.
CVE-2015-2375 exploits a vulnerability that allows attackers to bypass the ASLR protection mechanism.