Oval Definition:oval:org.mitre.oval:def:29449
Revision Date:2015-12-22Version:10
Title:Microsoft Office memory corruption vulnerability - CVE-2015-2380 (MS15-070)
Description:Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, and Word 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2015-2380
Platform(s):Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Product(s):Microsoft Word 2007
Microsoft Word 2010
Microsoft Word 2013
Microsoft Word Viewer
Definition Synopsis
  • Word 2007 and vulnerable file version
  • Microsoft Word 2007 is installed
  • AND Check if the version of winword.exe is less than 12.0.6726.5000
  • OR Word 2010 and vulnerable file version
  • Microsoft Word 2010 is installed
  • AND Check if the version of winword.exe is less than 14.0.7153.5002
  • OR Word 2013 and vulnerable file version
  • Microsoft Word 2013 is installed
  • AND Check if the version of winword.exe is less than 15.0.4737.1003
  • OR Word Viewer and vulnerable file version
  • Microsoft Word Viewer is installed
  • AND Check if the version of wordview.exe is less than 11.0.8419
  • BACK