CVE-2015-2431: Input Validation
Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2431?
CVE-2015-2431 has a CVSS base score of 7.8, indicating it is a high-severity vulnerability.
How do I fix CVE-2015-2431?
To fix CVE-2015-2431, you should apply the latest security updates provided by Microsoft for the affected software.
What software is affected by CVE-2015-2431?
CVE-2015-2431 affects Microsoft Office 2007 SP3, Office 2010 SP2, Live Meeting 2007 Console, and various versions of Lync.
What kind of attack vector is associated with CVE-2015-2431?
CVE-2015-2431 allows remote attackers to execute arbitrary code via a crafted Office Graphics Library font.
Are there any known exploits for CVE-2015-2431?
Yes, there are known exploits for CVE-2015-2431 that demonstrate how the vulnerability can be leveraged for remote code execution.