First published: Wed Nov 11 2015(Updated: )
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Word for Android | =2007-sp3 | |
Microsoft Word for Android | =2010-sp2 | |
Microsoft Word for Android | =2013-sp1 | |
Microsoft Word for Android | =2013-sp1 | |
Microsoft Word for Android | =2016 | |
Microsoft Word Viewer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6092 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2015-6092, ensure that you apply the latest security updates provided by Microsoft for the affected Office versions.
CVE-2015-6092 affects Microsoft Word 2007 SP3, 2010 SP2, 2013 SP1, 2016, and related Compatibility Pack and Viewer versions.
CVE-2015-6092 enables remote attackers to execute arbitrary code through specially crafted Office documents.
Mitigating the risks of CVE-2015-6092 involves training users on safe handling of Office documents and keeping software updated.