CVE-2015-2558: Use After Free
Use-after-free vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Excel Viewer, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a long fileVersion element in an Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2558?
CVE-2015-2558 is rated as critical due to its potential to allow remote code execution.
How do I fix CVE-2015-2558?
To address CVE-2015-2558, install the latest security updates released by Microsoft for affected versions of Excel.
Which Microsoft products are affected by CVE-2015-2558?
CVE-2015-2558 affects multiple versions of Microsoft Excel, Excel Viewer, Office Compatibility Pack, and SharePoint Server.
Can CVE-2015-2558 be exploited remotely?
Yes, CVE-2015-2558 can be exploited remotely if a user opens a specially crafted Excel file.
What types of attacks are possible through CVE-2015-2558?
CVE-2015-2558 may allow attackers to execute arbitrary code on the affected system.