CVE Vulnerabilities

CVE-2015-0086

Published: Mar 11, 2015 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 Gold and SP1, Word 2013 RT Gold and SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 Gold and SP1, Web Applications 2010 SP2, and Web Apps Server 2013 Gold and SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RTF document, aka Microsoft Office Memory Corruption Vulnerability.

Affected Software

Name Vendor Start Version End Version
Office Microsoft 2010-sp2 (including) 2010-sp2 (including)
Office_compatibility_pack Microsoft * *
Office_web_apps_server Microsoft 2013 (including) 2013 (including)
Office_web_apps_server Microsoft 2013-sp1 (including) 2013-sp1 (including)
Sharepoint_server Microsoft 2010-sp2 (including) 2010-sp2 (including)
Sharepoint_server Microsoft 2013 (including) 2013 (including)
Sharepoint_server Microsoft 2013-sp1 (including) 2013-sp1 (including)
Web_applications Microsoft 2010-sp2 (including) 2010-sp2 (including)
Word Microsoft 2007-sp3 (including) 2007-sp3 (including)
Word Microsoft 2010-sp2 (including) 2010-sp2 (including)
Word Microsoft 2013 (including) 2013 (including)
Word Microsoft 2013-sp1 (including) 2013-sp1 (including)
Word_viewer Microsoft * *

References