CVE-2015-2555: Use After Free
Use-after-free vulnerability in Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted calculatedColumnFormula object in an Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2555?
CVE-2015-2555 has been assigned a high severity rating due to the potential for remote code execution.
How do I fix CVE-2015-2555?
To fix CVE-2015-2555, you should apply the latest security updates provided by Microsoft for the affected versions of Excel and SharePoint.
Which software versions are affected by CVE-2015-2555?
CVE-2015-2555 affects Microsoft Excel 2010 SP2, 2013 SP1, 2016, Excel for Mac 2011, 2016, and SharePoint Server 2010 SP2 and 2013 SP1.
What type of vulnerability is CVE-2015-2555?
CVE-2015-2555 is a use-after-free vulnerability that can lead to arbitrary code execution.
Can CVE-2015-2555 be exploited remotely?
Yes, CVE-2015-2555 can be exploited remotely by attackers through crafted files that exploit the vulnerability.