CERT-In Vulnerability Note
CIVN-2015-0256
Multiple Vulnerabilities in Microsoft Office
Original Issue Date:October 14, 2015
Severity Rating: HIGH
Software Affected
- Microsoft Excel 2007 Service Pack 3
- Microsoft Visio 2007 Service Pack 3
- Microsoft Excel 2010 Service Pack 2 (32-bit and 64-bit editions)
- Microsoft Visio 2010 Service Pack 2 (32-bit and 64-bit editions)
- Microsoft Excel 2013 Service Pack 1 (32-bit and 64-bit editions)
- Microsoft Excel 2013 RT Service Pack 1
- Microsoft Excel 2016 (32-bit and 64-bit editions)
- Microsoft Excel for Mac 2011
- Microsoft Excel 2016 for Mac
- Microsoft Excel Viewer
- Microsoft Office Compatibility Pack Service Pack 3
- Microsoft SharePoint Server 2007 Service Pack 3 (32-bit and 64-bit editions)
- Microsoft SharePoint Server 2010 Service Pack 2
- Microsoft SharePoint Server 2013 Service Pack 1
- Microsoft Office Web Apps 2010 Service Pack 2
- Microsoft Excel Web App 2010 Service Pack 2
- Microsoft Office Web Apps Server 2013 Service Pack 1
- Microsoft SharePoint Foundation 2013 Service Pack 1
Overview
Multiple vulnerabilities have been reported in Microsoft Office which could allow a remote attacker to execute arbitrary code, disclosure of sensitive information, bypass security restrictions or conduct cross site scripting attacks on the targeted system with the privileges of the currently logged-in user.
Description
1. Multiple Memory Corruption Vulnerabilities
(
CVE-2015-2555
CVE-2015-2557
CVE-2015-2558
)
Multiple remote code execution vulnerabilities exist in Microsoft Office due to improper handling of objects in memory. A remote attacker could exploit these vulnerabilities by convincing a targeted user to open a malicious document or visit a specially crafted webpage that is designed to exploit the vulnerabilities. Successful exploitation of these vulnerabilities could allow a remote attacker to trigger memory corruption resulting in execution of arbitrary code in context of the currently logged-in user.
2. Microsoft SharePoint Information Disclosure Vulnerability
(
CVE-2015-2556
)
An Information Disclosure vulnerability in SharePoint InfoPath Forms Services exists due to improper parsing of the Document Type Definition (DTD) declarations while handling XML files. A remote attacker having write access to the affected site could exploit this vulnerability by uploading a malicious file and then sending a specially crafted HTTP request to the system. Successful exploitation of this vulnerability could allow a remote attacker to access the contents of arbitrary files on a SharePoint server and obtain sensitive information on the targeted system.
3. Microsoft Office Web Apps XSS Spoofing Vulnerability
(
CVE-2015-6037
)
This vulnerability exists in Microsoft Office Web Apps due to improper sanitization of user supplied input when processing crafted URLs. A remote attacker could exploit this vulnerability by enticing a user to visit the specially crafted link that takes the user to a targeted Office Web App site. Successful exploitation of this vulnerability could allow a remote attacker to perform the cross site scripting attacks on affected system.
4. Microsoft SharePoint Security Feature Bypass Vulnerability
(
CVE-2015-6039
)
This vulnerability exists in Microsoft SharePoint due to insufficient permissions enforcement while handling user supplied JavaScript. An attacker with the permissions to update the Marketplace instance could exploit this vulnerability by injecting malicious JavaScript to the application and then deploying the application to associated SharePoint instances. Successful exploitation of this vulnerability could allow a remote attacker to perform persistent cross site scripting attacks and run the malicious scripts to obtain sensitive information in the context of currently logged-in user.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS15-110
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/MS15-110
References
Microsoft
https://technet.microsoft.com/library/security/MS15-110
SecurityTracker
http://securitytracker.com/id/1033803
http://securitytracker.com/id/1033804
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=41363
http://tools.cisco.com/security/center/viewAlert.x?alertId=41365
http://tools.cisco.com/security/center/viewAlert.x?alertId=41366
http://tools.cisco.com/security/center/viewAlert.x?alertId=41364
http://tools.cisco.com/security/center/viewAlert.x?alertId=41367
http://tools.cisco.com/security/center/viewAlert.x?alertId=41369
CVE Name
CVE-2015-2556
CVE-2015-2557
CVE-2015-2558
CVE-2015-6037
CVE-2015-6039
CVE-2015-2555
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|