First published: Tue Jul 14 2015(Updated: )
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office for Mac | =2011 | |
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Office Word Viewer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2379 allows remote attackers to execute arbitrary code or cause denial of service through specially crafted Office documents.
CVE-2015-2379 affects Microsoft Word 2007 SP3, Office 2010 SP2, Word 2013 SP1, Office for Mac 2011, and Word Viewer.
CVE-2015-2379 is rated as critical due to the potential for remote code execution.
To fix CVE-2015-2379, apply the security updates provided by Microsoft for the affected versions of Office software.
Yes, CVE-2015-2379 can be exploited through specially crafted documents that may not require user interaction to trigger the vulnerability.