CVE-2015-2470
high · 9.3Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 2011, and Word Viewer allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Integer Underflow Vulnerability."
9.3
CVSS
26.9%
EPSS (exploit prob.)
98th
EPSS percentile
2015-08-15
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-189
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | office | 2010 |
| microsoft | office | 2010 |
| microsoft | office | 2011 |
| microsoft | office | 2013 |
| microsoft | word | 2007 |
| microsoft | word_viewer | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securitytracker.com/id/1033239
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-081
- https://www.exploit-db.com/exploits/37924/
- http://www.securitytracker.com/id/1033239
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-081
- https://www.exploit-db.com/exploits/37924/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-2470