HIGH · 9.3

CVE-2015-2431

Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted ...

Vulnerability Description

Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability."

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftLive Meeting2007
MicrosoftLync2010
MicrosoftLync Basic2013
MicrosoftOffice2010

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2431?

CVE-2015-2431 is a vulnerability with a CVSS score of 9.3 (HIGH). Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted ...

How severe is CVE-2015-2431?

CVE-2015-2431 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2431?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Live Meeting, Microsoft Lync, Microsoft Lync Basic, Microsoft Office.