Oval Definition:oval:org.mitre.oval:def:28513
Revision Date:2015-07-27Version:8
Title:Microsoft Office memory corruption vulnerability – CVE-2015-1760 (MS15-059)
Description:Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2015-1760
Platform(s):Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Office 2010
Microsoft Office 2013
Microsoft Office Compatibility Pack
Definition Synopsis
  • For Office Compatibility pack 2007 and its vulnerable file
  • Microsoft Office Compatibility Pack is installed
  • AND Check if the version of Wpft532.cnv is greater than or equal to 2006.1200.0000.0000
  • AND Check if the version of Wpft532.cnv is less than 2006.1200.6722.5000
  • OR For Office 2010 and its vulnerable file
  • Microsoft Office 2010 is installed
  • AND Check if the version of Wpft532.cnv is greater than or equal 2010.1400.0000.0000
  • AND Check if the version of Wpft532.cnv is less than 2010.1400.4730.1010
  • OR For Office 2013 and its vulnerable file
  • Microsoft Office 2013 is installed
  • AND vulnerable file
  • Check if the version of Wpft532.cnv is greater than or equal to 2012.1500.0000.0000 and less than 2012.1500.4727.1000
  • OR Check if the version of osf.dll is less than 15.0.4725.1000
  • BACK