9.3

CVE-2015-2424

Warnung
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Excel Viewer Version 2007 Update sp3
Microsoft ≫ Office Version 2007 Update sp3
Microsoft ≫ Office Version 2010 Update sp2
Microsoft ≫ Office Version 2011 SwPlatform macos
Microsoft ≫ Office Version 2013 Update sp1 SwEdition -
Microsoft ≫ Office Version 2013 Update sp1 SwEdition rt
Microsoft ≫ Office Compatibility Pack Version - Update sp3
Microsoft ≫ Powerpoint Version 2007 Update sp3
Microsoft ≫ Powerpoint Version 2010 Update sp2
Microsoft ≫ Word Version 2013 Update sp1
Microsoft ≫ Word Viewer Version -

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft PowerPoint Memory Corruption Vulnerability

Schwachstelle

Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 38.5% 0.984
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://www.securitytracker.com/id/1032899
Third Party Advisory
Broken Link
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-070
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2424
US Government Resource