Remote Code Execution Vulnerability in Microsoft Office and Lync Products
CVE-2015-2431
Currently unrated
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 15 August 2015
Badges
๐พ Exploit Exists๐ก Public PoC๐ฃ EPSS 64%
What is CVE-2015-2431?
Microsoft products, including several versions of Office and Lync, are susceptible to a vulnerability that allows remote attackers to execute arbitrary code. This can be achieved through specifically crafted Office Graphics Library fonts, posing a significant risk to users and organizations relying on these applications. Proper patching and awareness are essential to mitigate risks associated with this security flaw.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.