CVE-2015-2520
published 2015-09-09CVE-2015-2520: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute…
PriorityP266critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
27.69%
97.9th percentile
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit triggers a use-after-free via malformed BIFFRecord length fields in a crafted .xls file. Monitor for Excel processing .xls files with anomalous BIFFRecord lengths, specifically bit-flipped length values at file offsets 0x1CF7E and 0x3A966. ↗
- →The crash occurs in Excel!Ordinal40 when ESI holds a pointer to a freed heap allocation, indicating a use-after-free condition. Detection should focus on heap-use-after-free patterns in Excel.exe (version 12.0.6718.5000) and MSO.dll (version 12.0.6721.5000) during .xls file parsing. ↗
- →The vulnerability is specific to Microsoft Office 2007 (Excel.exe 12.0.6718.5000 / MSO.dll 12.0.6721.5000) and does NOT reproduce in Office 2010 or 2013. Scope detection rules accordingly. ↗
- →The crash instruction is a dereference of a freed heap pointer via ESI at Excel!Ordinal40+0x35a5ed (address 3035a5ed). This can be used as a precise crash/exploit signature for memory forensics or crash telemetry. ↗
- ·Reproduction requires Microsoft Office File Validation Add-In to be DISABLED. With the add-in enabled, the malicious file may be blocked before triggering the vulnerability. ↗
- ·The vulnerability only affects Excel 2007 SP3 (Excel.exe 12.0.6718.5000, MSO.dll 12.0.6721.5000) in the tested configuration. Detection rules targeting specific version strings or ordinal offsets should be scoped to this version. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
exploitdb·2015-09-16
CVE-2015-2520 Microsoft Office 2007 - BIFFRecord Length Use-After-Free
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=464
The following crash was observed in Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug did not reproduce in Office 2010 or 2013.
Attached files:
Original File: 1105668828_orig.xls
Crashing File: 1105668828_crash.xls
Minimized Crashing File: 1105668828_min.xls
The minimized crashing file shows two one bit deltas from the original file. The first delta at offset 0x1CF7E and the second is at offset 0x3A966. Both of these offset appear to be BIFFRecord lengths.
File Versions:
Excel.exe: 12.0.6718.5000
MSO.dll: 12.0.6721.5000
Observed Crash:
eax=0000000
Exploit-DB
Zhone GPON 2520 R4.0.2.566b - Crash (PoC)
exploitdb·2015-01-21
CVE-2015-2055 Zhone GPON 2520 R4.0.2.566b - Crash (PoC)
Zhone GPON 2520 R4.0.2.566b - Crash (PoC)
---
from httplib2 import Http
from urllib import urlencode
import sys,time
#main function
if __name__ == "__main__":
if(len(sys.argv) != 2):
print '*********************************************************************************'
print ' GPON Zhone R4.0.2.566b D.O.S.'
print ' Tested on'
print ' GPON Zhone 2520'
print ' Hardware: 0040-48-02'
print ' Software: R4.0.2.566b'
print ' '
print ' Usage : python', sys.argv[0] + ' '
print ' Ex : python',sys.argv[0] + ' 192.168.15.1'
print ' Author : Kaczinski [email protected] '
print ' URL : http://www.websec.mx/advisories'
print '*********************************************************************************'
sys.exit()
HOST = sys.argv[1]
LIMIT = 100000
COUNT = 1
SIZE = 10
BUFFER = ''
while len(BUF
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated CriticalMS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this month which affected Internet Explorer versions
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
## Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated Critical MS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this m
http://www.securitytracker.com/id/1033488https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099https://www.exploit-db.com/exploits/38215/http://www.securitytracker.com/id/1033488https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099https://www.exploit-db.com/exploits/38215/
2015-09-09
Published