First published: Wed Oct 14 2015(Updated: )
Use-after-free vulnerability in Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted calculatedColumnFormula object in an Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac | =2010-sp2 | |
Microsoft Excel for Mac | =2010-sp2 | |
Microsoft Excel for Mac | =2013-sp1 | |
Microsoft Excel for Mac | =2013-sp1 | |
Microsoft Excel | =2011 | |
Microsoft Excel | =2016 | |
Microsoft SharePoint Server | =2010-sp2 | |
Microsoft SharePoint Server | =2013-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2555 has been assigned a high severity rating due to the potential for remote code execution.
To fix CVE-2015-2555, you should apply the latest security updates provided by Microsoft for the affected versions of Excel and SharePoint.
CVE-2015-2555 affects Microsoft Excel 2010 SP2, 2013 SP1, 2016, Excel for Mac 2011, 2016, and SharePoint Server 2010 SP2 and 2013 SP1.
CVE-2015-2555 is a use-after-free vulnerability that can lead to arbitrary code execution.
Yes, CVE-2015-2555 can be exploited remotely by attackers through crafted files that exploit the vulnerability.