CVE-2015-2466: Input Validation
Published Aug 15, 2015
·Updated
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted template, aka "Microsoft Office Remote Code Execution Vulnerability."
Affected Software
3 affected components
Microsoft Office=2007-sp3
Microsoft Office=2010-sp1
Microsoft Office=2013-sp1
Event History
Aug 15, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2466?
CVE-2015-2466 has a critical severity rating, indicating it poses a significant risk to affected systems.
2
How do I fix CVE-2015-2466?
To fix CVE-2015-2466, users should apply the security updates provided by Microsoft for their specific versions of Office.
3
Which Microsoft Office versions are affected by CVE-2015-2466?
CVE-2015-2466 affects Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1.
4
What type of attack does CVE-2015-2466 allow?
CVE-2015-2466 allows remote attackers to execute arbitrary code through the use of a crafted template.
5
Is it possible to exploit CVE-2015-2466 without user interaction?
Yes, CVE-2015-2466 can be exploited remotely, potentially without user interaction, by tricking a user into opening a malicious document.