First published: Tue Jul 14 2015(Updated: )
Untrusted search path vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 SP3, and Office Compatibility Pack SP3 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Microsoft Excel DLL Remote Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp3 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel Viewer | =2007-sp3 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2378 is considered to have a high severity due to its potential for remote code execution.
To fix CVE-2015-2378, you should apply the security updates provided by Microsoft for the affected versions of Excel and Office.
CVE-2015-2378 affects Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 SP3, and the Office Compatibility Pack SP3.
CVE-2015-2378 is an untrusted search path vulnerability allowing local users to gain elevated privileges.
Yes, CVE-2015-2378 can be exploited by attackers through the use of a Trojan horse DLL placed in the current working directory.