First published: Sat Aug 15 2015(Updated: )
Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Live Meeting | =2007 | |
Microsoft Lync | =2010 | |
Microsoft Lync | =2010 | |
Microsoft Lync | =2010 | |
Microsoft Lync Basic | =2013-sp1 | |
Microsoft Lync Basic | =2013-sp1 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2431 has a CVSS base score of 7.8, indicating it is a high-severity vulnerability.
To fix CVE-2015-2431, you should apply the latest security updates provided by Microsoft for the affected software.
CVE-2015-2431 affects Microsoft Office 2007 SP3, Office 2010 SP2, Live Meeting 2007 Console, and various versions of Lync.
CVE-2015-2431 allows remote attackers to execute arbitrary code via a crafted Office Graphics Library font.
Yes, there are known exploits for CVE-2015-2431 that demonstrate how the vulnerability can be leveraged for remote code execution.