KLA10551
Code execution vulnerabilities in Microsoft Office

Обновлено: 03/06/2020
Дата обнаружения
14/04/2015
Уровень угрозы
Critical
Описание

Use-after-free, XSS and aother unspecified vulnerabilities were found in Microsoft products. By exploiting these vulnerabilities malicious users can execute or inject arbitrary code. These vulnerabilities can be exploited remotely via a specially designed Office document.

Пораженные продукты

Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 x86, x64 Service Pack 2
Microsoft Office 2013 x86, x64, RT Service Pack1
Microsoft Word Viewer
Microsoft Office Compatibility Pack Service Pack 3
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft SharePoinr Server 2013 Service Pack 1
Microsoft Office Web Apps 2010 Service Pack 2
Microsoft Office Web Apps 2013 Service Pack 1

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
MS15-033
CVE-2015-0204
CVE-2015-0484
CVE-2015-0492
CVE-2015-0469
CVE-2015-0478
CVE-2015-0480
CVE-2015-0477
CVE-2015-0458
CVE-2015-0459
CVE-2015-0470
CVE-2015-0488
CVE-2015-0486
CVE-2015-0491
CVE-2015-0460
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

LoI 
[?]
Связанные продукты
Microsoft Office
CVE-IDS
CVE-2015-02044.3Warning
CVE-2015-04846.8High
CVE-2015-04929.3Critical
CVE-2015-04784.3Warning
CVE-2015-04805.8High
CVE-2015-04774.3Warning
CVE-2015-04587.6Critical
CVE-2015-04704.3Warning
CVE-2015-04885.0Critical
CVE-2015-04865.0Critical
CVE-2015-04609.3Critical