Microsoft Office Component Use After Free Vulnerability (CVE-2015-1649)
Publish date: 06 de abril de 2016
Gravedad: Crítico
Identificadores de CVE : 2015-1649,MS15-033
Fecha recomendada: 06 de abril de 2016
Descripción
A remote code execution vulnerability exists in Microsoft Office software that is caused when the Office software improperly handles objects in memory while parsing specially crafted Office files. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.
Trend Micro researcher Jack Tang disclosed details about this vulnerability to Microsoft. The said company acknowledged Tang’s research contribution.
Revelación de la información
Apply associated Trend Micro DPI Rules.
Soluciones
Trend Micro Deep Security DPI Rule Name: 1006625 - Microsoft Office Component Use After Free Vulnerability (CVE-2015-1649)
Software y versión afectados
- Microsoft Office