Oval Definition:oval:org.mitre.oval:def:29525
Revision Date:2015-12-22Version:13
Title:Microsoft Excel DLL remote code execution vulnerability - CVE-2015-2378 (MS15-070)
Description:Untrusted search path vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 SP3, and Office Compatibility Pack SP3 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Microsoft Excel DLL Remote Code Execution Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2015-2378
Platform(s):Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Product(s):Microsoft Excel 2007
Microsoft Excel 2010
Microsoft Excel Viewer 2007
Microsoft Office Compatibility Pack
Definition Synopsis
  • Excel 2007 and vulnerable file version
  • Microsoft Excel 2007 is installed
  • AND Check if the version of excel.exe is less than 12.0.6723.5000
  • OR Excel 2010 and vulnerable file version
  • Microsoft Excel 2010 is installed
  • AND Check if the version of excel.exe is less than 14.0.7153.5000
  • OR Excel Viewer and vulnerable file version
  • Microsoft Excel Viewer 2007 is installed
  • AND Check if the version of xlview.exe is less than 12.0.6723.5000
  • OR Office Compatibility Pack 2007 and vulnerable version
  • Microsoft Office Compatibility Pack is installed
  • AND Check if the version of excelcnv.exe is less than 12.0.6723.5000
  • BACK