← All CVEs

CVE-2015-2423

medium · 4.3

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Visio 2013 RT SP1, Word 2013 RT SP1, and Internet Explorer 7 through 11 allow remote attackers to gain privileges and obtain sensitive information via a crafted command-line parameter to an Office application or Notepad, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Unsafe Command Line Parameter Passing Vulnerability."

4.3
CVSS
19.9%
EPSS (exploit prob.)
97th
EPSS percentile
2015-08-15
Published

AV:N/AC:M/Au:N/C:P/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
microsoftexcel2007
microsoftexcel2010
microsoftexcel2013
microsoftexcel2013
microsoftoffice2010
microsoftpowerpoint2007
microsoftpowerpoint2010
microsoftpowerpoint2013
microsoftpowerpoint2013
microsoftvisio2007
microsoftvisio2010
microsoftvisio2013
microsoftvisio2013
microsoftvisio2016
microsoftword2007
microsoftword2010
microsoftword2013
microsoftword2013
microsoftword2016
microsoftinternet_explorer7
microsoftinternet_explorer8
microsoftinternet_explorer9
microsoftinternet_explorer10
microsoftinternet_explorer11
microsoftwindows_10all versions
microsoftwindows_7all versions
microsoftwindows_8all versions
microsoftwindows_8.1all versions
microsoftwindows_rtall versions
microsoftwindows_rt_8.1all versions
microsoftwindows_server_2008all versions
microsoftwindows_server_2008r2
microsoftwindows_server_2008r2
microsoftwindows_server_2012all versions
microsoftwindows_server_2012r2
microsoftwindows_vistaall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-2423