Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.805809
Category:Windows : Microsoft Bulletins
Title:Microsoft Office Excel Multiple Remote Code Execution Vulnerabilities (3072620)
Summary:This host is missing an important security; update according to Microsoft Bulletin MS15-070.
Description:Summary:
This host is missing an important security
update according to Microsoft Bulletin MS15-070.

Vulnerability Insight:
Multiple flaws exist when,

- Microsoft Excel improperly handles the loading of dynamic link library
(DLL) files.

- Error when memory is released in an unintended manner.

- Improper handling of files in the memory.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to run arbitrary code in the context of the current user and
to perform actions in the security context of the current user.

Affected Software/OS:
- Microsoft Excel 2007 Service Pack 3 and prior

- Microsoft Excel 2010 Service Pack 2 and prior

- Microsoft Excel 2013 Service Pack 1 and prior

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-2376
Microsoft Security Bulletin: MS15-070
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-070
http://www.securitytracker.com/id/1032899
Common Vulnerability Exposure (CVE) ID: CVE-2015-2377
Common Vulnerability Exposure (CVE) ID: CVE-2015-2415
Common Vulnerability Exposure (CVE) ID: CVE-2015-2378
Common Vulnerability Exposure (CVE) ID: CVE-2015-2375
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.