CVE-2015-2521
published 2015-09-09CVE-2015-2521: Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office…
PriorityP266critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
27.69%
97.9th percentile
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The malicious .xls file triggers a type confusion via a crafted OLESSDirectoryEntry.CreateTime field. The one-bit delta from the original file occurs at file offset 0x49E8 — monitor for XLS files with anomalous OLE Structured Storage directory entry CreateTime values. ↗
- →Exploitation results in EIP corruption to 0xfffffffc via a corrupted function pointer dereference in Excel!Ordinal40. A crash at EIP=0xfffffffc in Excel.exe (version 12.0.6718.5000) processing an XLS file is a strong exploitation indicator. ↗
- →The vulnerability involves an out-of-bounds read at offset 0x3F0 into a heap allocation of only 0x1B0 bytes, consistent with a type confusion. Heap page fault at eax+0x3F0 where the allocation size is 0x1B0 in Excel!Ordinal40 is a detection signal. ↗
- →Affected Excel.exe version is 12.0.6718.5000 and MSO.dll version is 12.0.6721.5000 (Office 2007 SP3). Use version-based detection to identify unpatched installations. ↗
- ·The crash and exploitation path were only confirmed in Office 2007 with the Microsoft Office File Validation Add-In disabled. The bug did not reproduce in Office 2010 or 2013, limiting the scope of detection to Office 2007 SP3 targets. ↗
- ·Application Verifier must be enabled to observe the root-cause crash (heap out-of-bounds access); without it, only the downstream EIP corruption is visible. Production detections should not rely on Application Verifier being present. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated CriticalMS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this month which affected Internet Explorer versions
Talos
Microsoft Patch Tuesday - September 2015
blogs_talos·2015-09-08·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - September 2015
## Microsoft Patch Tuesday - September 2015
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 12 bulletins released which address 55 CVEs. Five bulletins are rated "Critical" this month and address vulnerabilities in Edge, Graphics Component, Internet Explorer, Journal, and Office. The other seven bulletins are rated "Important" and address vulnerabilities in the .NET Framework, Active Directory, Exchange, Hyper-V, Media Center, Skype for Business, and Task Management.
## Bulletins Rated Critical MS15-094, MS15-095, MS15-097, MS-098, and MS15-099 are rated "Critical".
MS15-094 is this month's Internet Explorer security bulletin. Seventeen CVEs are addressed this m
http://www.securitytracker.com/id/1033488https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099https://www.exploit-db.com/exploits/38216/http://www.securitytracker.com/id/1033488https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099https://www.exploit-db.com/exploits/38216/
2015-09-09
Published