Security bypass in Microsoft products - CVE-2015-2375
Published: January 31, 2017 / Updated: March 10, 2017
Vulnerability identifier: #VU5561
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-2375
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass Address Space Layout Randomization on the target system.
The weakness exists due to insecure memory release. A remote attacker can create a specially crafted Excel file, trick the victim into opening it and bypass ASLR mechanism.
Successful exploitation of this vulnerability results in security bypass on the vulnerable system.
The weakness exists due to insecure memory release. A remote attacker can create a specially crafted Excel file, trick the victim into opening it and bypass ASLR mechanism.
Successful exploitation of this vulnerability results in security bypass on the vulnerable system.
Affected software
Microsoft Office
Microsoft Excel
Microsoft SharePoint Server
Microsoft Excel
Microsoft SharePoint Server
How to mitigate CVE-2015-2375
Install update from vendor's website.