Remote Code Execution Vulnerability in Microsoft Word and SharePoint Products
CVE-2015-0064
Currently unrated
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 11 February 2015
Badges
๐พ Exploit Exists๐ก Public PoC๐ฃ EPSS 71%
What is CVE-2015-0064?
This vulnerability in Microsoft Word and related products allows attackers to execute arbitrary code or trigger a denial of service through specially crafted Office documents. The affected versions include Microsoft Word 2007 SP3, Office 2010 SP2, and various SharePoint components. Exploiting this vulnerability can lead to unauthorized actions on the target system, emphasizing the need for immediate mitigation measures and awareness of safe document handling practices.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.