Security bypass in Microsoft products - CVE-2015-2375

 

Security bypass in Microsoft products - CVE-2015-2375

Published: January 31, 2017 / Updated: March 10, 2017


Vulnerability identifier: #VU5561
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-2375
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass Address Space Layout Randomization on the target system.

The weakness exists due to insecure memory release. A remote attacker can create a specially crafted Excel file, trick the victim into opening it and bypass ASLR mechanism.

Successful exploitation of this vulnerability results in security bypass on the vulnerable system.

Affected software

Microsoft Office
Microsoft Excel
Microsoft SharePoint Server

How to mitigate CVE-2015-2375

Install update from vendor's website.


External References

Related Security Bulletins