Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1203 | broken link third party advisory vdb entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-081 | patch vendor advisory |
http://www.securitytracker.com/id/1033239 | broken link third party advisory vdb entry |