First published: Wed Sep 09 2015(Updated: )
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp3 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Excel | =2011 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Excel | =2016 | |
Microsoft Office Excel Viewer | ||
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2523 is classified as a critical vulnerability allowing remote code execution.
To fix CVE-2015-2523, apply the latest security updates provided by Microsoft for the affected versions of Excel.
CVE-2015-2523 affects Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel for Mac 2011 and 2016, Excel Viewer, and the Office Compatibility Pack SP3.
CVE-2015-2523 involves remote attackers executing arbitrary code via a crafted Office document.
Yes, CVE-2015-2523 can be exploited automatically when a victim opens a malicious Excel document.