Microsoft Security Bulletin MS15-046 - Important

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3057181)

Published: May 12, 2015 | Updated: October 13, 2015

Version: 4.0

Executive Summary

This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

This security update is rated Important****for all supported editions of the following software:

  • Microsoft Office 2007
  • Microsoft Office 2010, Microsoft Excel 2010, Microsoft PowerPoint 2010, Microsoft Word 2010
  • Microsoft Office 2013, Microsoft Excel 2013, Microsoft PowerPoint 2013, Microsoft Word 2013
  • Microsoft Office 2013 RT, Microsoft Excel 2013 RT, Microsoft PowerPoint 2013 RT, Microsoft Word 2013 RT
  • Microsoft Office for Mac 2011, Microsoft Excel for Mac 2011, Microsoft PowerPoint for Mac 2011, Microsoft Word for Mac 2011
  • Microsoft PowerPoint Viewer
  • Word Automation Services on Microsoft SharePoint Server 2010, Excel Services on Microsoft SharePoint Server 2010
  • Word Automation Services on Microsoft SharePoint Server 2013, Excel Services on Microsoft SharePoint Server 2013
  • Microsoft Office Web Apps 2010, Microsoft Excel Web App 2010
  • Microsoft Office Web Apps Server 2013
  • Microsoft SharePoint Foundation 2010
  • Microsoft SharePoint Server 2013

For more information, see the Affected Software section.

The security update addresses the vulnerabilities by correcting how Microsoft Office parses specially crafted files, by correcting how Office handles files in memory, and by helping to ensure that SharePoint Server properly sanitizes user input. For more information about the vulnerabilities, see the Vulnerability Information section.

For more information about this update, see Microsoft Knowledge Base Article 3057181.

Affected Software

The following software versions or editions are affected. Versions or editions that are not listed are either past their support life cycle or are not affected. To determine the support life cycle for your software version or edition, see Microsoft Support Lifecycle.

Microsoft Office Software

Microsoft Office Suites Software Component Maximum Security Impact Aggregate Severity Rating Updates Replaced
Microsoft Office 2007
Microsoft Office 2007 Service Pack 3
(3085544)
Not applicable Remote Code Execution Important 3054888 in MS15-081
Microsoft Office 2010
Microsoft Office 2010 Service Pack 2 (32-bit editions)
(3054841)
Not applicable Remote Code Execution Important 2965236 in MS15-033
Microsoft Office 2010 Service Pack 2 (64-bit editions)
(3054841)
Not applicable Remote Code Execution Important 2965236 in MS15-033
Microsoft Office 2010 Service Pack 2 (32-bit editions)
(3054834)
Not applicable Remote Code Execution Important 2883100 in MS15-022
Microsoft Office 2010 Service Pack 2 (64-bit editions)
(3054834)
Not applicable Remote Code Execution Important 2883100 in MS15-022
Microsoft Office 2010 Service Pack 2 (32-bit editions)
(3054848)
Not applicable Remote Code Execution Important 2889839 in MS15-022
Microsoft Office 2010 Service Pack 2 (64-bit editions)
(3054848)
Not applicable Remote Code Execution Important 2889839 in MS15-022
Microsoft Office 2010 Service Pack 2 (32-bit editions) Microsoft Excel 2010 Service Pack 2 (32-bit editions)
(3054845)
Remote Code Execution Important 2956142 in MS15-022
Microsoft Office 2010 Service Pack 2 (64-bit editions) Microsoft Excel 2010 Service Pack 2 (64-bit editions)
(3054845)
Remote Code Execution Important 2956142 in MS15-022
Microsoft Office 2010 Service Pack 2 (32-bit editions) Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions)
(3054835)
Remote Code Execution Important None
Microsoft Office 2010 Service Pack 2 (64-bit editions) Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions)
(3054835)
Remote Code Execution Important None
Microsoft Office 2010 Service Pack 2 (32-bit editions) Microsoft Word 2010 Service Pack 2 (32-bit editions)
(3054842)
Remote Code Execution Important 2956139 in MS15-022
Microsoft Office 2010 Service Pack 2 (64-bit editions) Microsoft Word 2010 Service Pack 2 (64-bit editions)
(3054842)
Remote Code Execution Important 2956139 in MS15-022
Microsoft Office 2013
Microsoft Office 2013 Service Pack 1 (32-bit editions)
(2975808)
Not applicable Remote Code Execution Important 2817623 in MS13-085
Microsoft Office 2013 Service Pack 1 (64-bit editions)
(2975808)
Not applicable Remote Code Execution Important 2817623 in MS13-085
Microsoft Office 2013 Service Pack 1 (32-bit editions) Microsoft Excel 2013 Service Pack 1 (32-bit editions)
(2986216)
Remote Code Execution Important 2920753 in MS15-012
Microsoft Office 2013 Service Pack 1 (64-bit editions) Microsoft Excel 2013 Service Pack 1 (64-bit editions)
(2986216)
Remote Code Execution Important 2920753 in MS15-012
Microsoft Office 2013 Service Pack 1 (32-bit editions) Microsoft PowerPoint 2013 Service Pack 1 (32-bit editions)
(2975816)
Remote Code Execution Important None
Microsoft Office 2013 Service Pack 1 (64-bit editions) Microsoft PowerPoint 2013 Service Pack 1 (64-bit editions)
(2975816)
Remote Code Execution Important None
Microsoft Office 2013 Service Pack 1 (32-bit editions) Microsoft Word 2013 Service Pack 1 (32-bit editions)
(2965307)
Remote Code Execution Important 2965224 in MS15-033
Microsoft Office 2013 Service Pack 1 (64-bit editions) Microsoft Word 2013 Service Pack 1 (64-bit editions)
(2965307)
Remote Code Execution Important 2965224 in MS15-033
Microsoft Office 2013 RT
Microsoft Office 2013 RT Service Pack 1
(2975808) [1]
Not applicable Remote Code Execution Important 2817623 in MS13-085
Microsoft Office 2013 RT Service Pack 1 Microsoft Excel 2013 RT Service Pack 1
(2986216) [1]
Remote Code Execution Important 2920753 in MS15-012
Microsoft Office 2013 RT Service Pack 1 Microsoft PowerPoint 2013 RT Service Pack 1
(2975816) [1]
Remote Code Execution Important None
Microsoft Office 2013 RT Service Pack 1 Microsoft Word 2013 RT Service Pack 1
(2965307) [1]
Remote Code Execution Important 2965224 in MS15-033
Microsoft Office for Mac
Microsoft Office for Mac 2011
(3048688)
Not applicable Remote Code Execution Important 3051737 in MS15-033 and 3062536, formerly provided in this bulletin.
Microsoft Office for Mac 2011 Microsoft Excel for Mac 2011
(3048688)
Remote Code Execution Important 3051737 in MS15-033 and 3062536, formerly provided in this bulletin.
Microsoft Office for Mac 2011 Microsoft PowerPoint for Mac 2011
(3048688)
Remote Code Execution Important 3051737 in MS15-033 and 3062536, formerly provided in this bulletin.
Microsoft Office for Mac 2011 Microsoft Word for Mac 2011
(3048688)
Remote Code Execution Important 3051737 in MS15-033 and 3062536, formerly provided in this bulletin.
Other Office Software
Microsoft PowerPoint Viewer
(3054840)
Not applicable Remote Code Execution Important None

[1]This update is available via Windows Update.

Microsoft Office Services and Web Apps

Microsoft Office Services and Web Apps Component Maximum Security Impact Aggregate Severity Rating Updates Replaced
Microsoft SharePoint Server 2010
Microsoft SharePoint Server 2010 Service Pack 2 Word Automation Services
(3054833)
Remote Code Execution Important 2956136 in MS15-022
Microsoft SharePoint Server 2010 Service Pack 2 Excel Services
(3054839)
Remote Code Execution Important 2826029 in MS13-084
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2013 Service Pack 1 Word Automation Services
(3023055)
Remote Code Execution Important 2965215 in MS15-033
Microsoft SharePoint Server 2013 Service Pack 1 Excel Services
(3039725)
Remote Code Execution Important 2956143 in MS15-022
Microsoft Office Web Apps 2010
Microsoft Office Web Apps 2010 Service Pack 2
(3054843)
Not applicable Remote Code Execution Important 2956070 in MS15-012
Microsoft Office Web Apps 2010 Service Pack 2 Microsoft Excel Web Apps 2010 Service Pack 2
(3054838)
Remote Code Execution Important 2826028 in MS13-084
Microsoft Office Web Apps 2013
Microsoft Office Web Apps Server 2013 Service Pack 1[2] (3039748) Not applicable Remote Code Execution Important 2965306 in MS15-033

[2] Office Web Apps Server cannot be updated via automatic updating. For recommended instructions on how to apply updates to Office Web Apps Server, see Apply software updates to Office Web Apps Server.


Microsoft Server Software

Microsoft Office Services and Web Apps Component Maximum Security Impact Aggregate Severity Rating Updates Replaced
Microsoft SharePoint Server 2010
Microsoft SharePoint Server 2010 Service Pack 2 Microsoft SharePoint Foundation 2010 Service Pack 2
(3054847)
Remote Code Execution Important 2956208 in MS15-022
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2013 Service Pack 1
(3039736)
Not applicable Remote Code Execution Important 2760561 in MS13-084

Update FAQ

Why are some of the update files listed in this bulletin also denoted in other bulletins being released in May?
Several of the update files listed in this bulletin are also denoted in other bulletins being released in May due to overlaps in affected software. Although the different bulletins address separate security vulnerabilities, the security updates have been consolidated where possible and appropriate. Therefore some identical update files are present in multiple bulletins.

Note that identical update files being released with multiple bulletins do not need to be installed more than once.

Does this update contain any additional security-related changes to functionality?
Yes. In addition to the changes that are listed for the vulnerabilities described in this bulletin, this update includes defense-in-depth updates to help make Microsoft Office more secure.

I have Microsoft Word 2010 installed. Why am I not being offered the 3054841update?
The 3054841update only applies to systems running specific configurations of Microsoft Office 2010. Some configurations will not be offered the update.

There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Affected Software table for the software?
Yes. Customers should apply all updates offered for the software installed on their systems.

I am being offered this update for software that is not specifically listed in the Affected Software table. Why am I being offered this update?
When updates address vulnerable code that exists in a component that is shared between multiple Microsoft Office products or shared between multiple versions of the same Microsoft Office product, the update is considered to be applicable to all supported products and versions that contain the vulnerable component.

For example, when an update applies to Microsoft Office 2007 products, only Microsoft Office 2007 may be specifically listed in the Affected Software table. However, the update could apply to Microsoft Word 2007, Microsoft Excel 2007, Microsoft Visio 2007, Microsoft Compatibility Pack, Microsoft Excel Viewer, or any other Microsoft Office 2007 product that is not specifically listed in the Affected Software table.

For example, when an update applies to Microsoft Office 2010 products, only Microsoft Office 2010 may be specifically listed in the Affected Software table. However, the update could apply to Microsoft Word 2010, Microsoft Excel 2010, Microsoft Visio 2010, Microsoft Visio Viewer, or any other Microsoft Office 2010 product that is not specifically listed in the Affected Software table.

For example, when an update applies to Microsoft Office 2013 products, only Microsoft Office 2013 may be specifically listed in the Affected Software table. However, the update could apply to Microsoft Word 2013, Microsoft Excel 2013, Microsoft Visio 2013, or any other Microsoft Office 2013 product that is not specifically listed in the Affected Software table.

Severity Ratings and Vulnerability Identifiers

The following severity ratings assume the potential maximum impact of the vulnerability. For information regarding the likelihood, within 30 days of this security bulletin's release, of the exploitability of the vulnerability in relation to its severity rating and security impact, please see the Exploitability Index in the May bulletin summary.

Microsoft Office Software

Vulnerability Severity Rating and Maximum Security Impact by Affected Software
Affected Software Microsoft Office Memory Corruption Vulnerability – CVE-2015-1682 Microsoft Office Memory Corruption Vulnerability – CVE-2015-1683 Aggregate Severity Rating
Microsoft Office 2007
Microsoft Office 2007 Service Pack 3 Not applicable Important
Remote Code Execution
(3085544)
Important
Microsoft Office 2010
Microsoft Office 2010 Service Pack 2 (32-bit editions) Important
Remote Code Execution
(3054841)
Not applicable Important
Microsoft Office 2010 Service Pack 2 (64-bit editions) Important
Remote Code Execution
(3054841)
Not applicable Important
Microsoft Office 2010 Service Pack 2 (32-bit editions) Important
Remote Code Execution
(3054834)
Not applicable Important
Microsoft Office 2010 Service Pack 2 (64-bit editions) Important
Remote Code Execution
(3054834)
Not applicable Important
Microsoft Office 2010 Service Pack 2 (32-bit editions) Important
Remote Code Execution
(3054848)
Not applicable Important
Microsoft Office 2010 Service Pack 2 (64-bit editions) Important
Remote Code Execution
(3054848)
Not applicable Important
Microsoft Excel 2010 Service Pack 2 (32-bit editions) Important
Remote Code Execution
(3054845)
Not applicable Important
Microsoft Excel 2010 Service Pack 2 (64-bit editions) Important
Remote Code Execution
(3054845)
Not applicable Important
Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions) Important
Remote Code Execution
(3054835)
Not applicable Important
Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions) Important
Remote Code Execution
(3054835)
Not applicable Important
Microsoft Word 2010 Service Pack 2 (32-bit editions) Important
Remote Code Execution
(3054842)
Not applicable Important
Microsoft Word 2010 Service Pack 2 (64-bit editions) Important
Remote Code Execution
(3054842)
Not applicable Important
Microsoft Office 2013
Microsoft Office 2013 Service Pack 1 (32-bit editions) Important
Remote Code Execution
(2975808)
Not applicable Important
Microsoft Office 2013 Service Pack 1 (64-bit editions) Important
Remote Code Execution
(2975808)
Not applicable Important
Microsoft Excel 2013 Service Pack 1 (32-bit editions) Important
Remote Code Execution
(2986216)
Not applicable Important
Microsoft Excel 2013 Service Pack 1 (64-bit editions) Important
Remote Code Execution
(2986216)
Not applicable Important
Microsoft PowerPoint 2013 Service Pack 1 (32-bit editions) Important
Remote Code Execution
(2975816)
Not applicable Important
Microsoft PowerPoint 2013 Service Pack 1 (64-bit editions) Important
Remote Code Execution
(2975816)
Not applicable Important
Microsoft Word 2013 Service Pack 1 (32-bit editions) Important
Remote Code Execution
(2965307)
Not applicable Important
Microsoft Word 2013 Service Pack 1 (64-bit editions) Important
Remote Code Execution
(2965307)
Not applicable Important
Microsoft Office 2013 RT
Microsoft Office 2013 RT Service Pack 1 Important
Remote Code Execution
(2975808)
Not applicable Important
Microsoft Excel 2013 RT Service Pack 1 Important
Remote Code Execution
(2986216)
Not applicable Important
Microsoft PowerPoint 2013 RT Service Pack 1 Important
Remote Code Execution
(2975816)
Not applicable Important
Microsoft Word 2013 RT Service Pack 1 Important
Remote Code Execution
(2965307)
Not applicable Important
Microsoft Office for Mac
Microsoft Office for Mac 2011 Important
Remote Code Execution
(3048688)
Not applicable Important
Microsoft Excel for Mac 2011 Important
Remote Code Execution
(3048688)
Not applicable Important
Microsoft PowerPoint for Mac 2011 Important
Remote Code Execution
(3048688)
Not applicable Important
Microsoft Word for Mac 2011 Important
Remote Code Execution
(3048688)
Not applicable Important
Other Office Software
Microsoft PowerPoint Viewer Important
Remote Code Execution
(3054840)
Not applicable Important

Microsoft Office Services and Web Apps

Vulnerability Severity Rating and Maximum Security Impact by Affected Software
Affected Software Microsoft Office Memory Corruption Vulnerability – CVE-2015-1682 Microsoft Office Memory Corruption Vulnerability – CVE-2015-1683 Aggregate Severity Rating
Microsoft SharePoint Server 2010
Word Automation Services on Microsoft SharePoint Server 2010 Service Pack 2 Important
Remote Code Execution
(3054833)
Not applicable Important
Excel Services on Microsoft SharePoint Server 2010 Service Pack 2 Important
Remote Code Execution
(3054839)
Not applicable Important
Microsoft SharePoint Server 2013
Word Automation Services on Microsoft SharePoint Server 2013 Service Pack 1 Important
Remote Code Execution
(3023055)
Not applicable Important
Excel Services on Microsoft SharePoint Server 2013 Service Pack 1 Important
Remote Code Execution
(3039725)
Not applicable Important
Microsoft Office Web Apps 2010
Microsoft Office Web Apps 2010 Service Pack 2 Important
Remote Code Execution
(3054843)
Not applicable Important
Microsoft Excel Web App 2010 Service Pack 2 Important
Remote Code Execution
(3054838)
Not applicable Important
Microsoft Office Web Apps 2013
Microsoft Office Web Apps Server 2013 Service Pack 1 Important
Remote Code Execution
(3039748)
Not applicable Important

Microsoft Server Software

Vulnerability Severity Rating and Maximum Security Impact by Affected Software
Affected Software Microsoft Office Memory Corruption Vulnerability – CVE-2015-1682 Microsoft Office Memory Corruption Vulnerability – CVE-2015-1683 Aggregate Severity Rating
Microsoft SharePoint Server 2010
Microsoft SharePoint Foundation 2010 Service Pack 2 Important
Remote Code Execution
(3054847)
Not applicable Important
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2013 Service Pack 1 Important
Remote Code Execution
(3039736)
Not applicable Important

Vulnerability Information

Multiple Microsoft Office Memory Corruption Vulnerabilities

Remote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory.

Exploitation of these vulnerabilities requires that a user open a specially crafted file with an affected version of Microsoft Office software. In an email attack scenario an attacker could exploit the vulnerabilities by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerabilities. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or Instant Messenger message.

An attacker who successfully exploited these vulnerabilities could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

The security update addresses the vulnerabilities by correcting how Microsoft Office parses specially crafted files.

Microsoft received information about the vulnerabilities through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that these vulnerabilities had been publicly used to attack customers.

The following tables contain links to the standard entry for each vulnerability in the Common Vulnerabilities and Exposures list:

Vulnerability title CVE number Publicly Disclosed Exploited
Microsoft Office Memory Corruption Vulnerability CVE-2015-1682 No No
Microsoft Office Memory Corruption Vulnerability CVE-2015-1683 No No

Mitigating Factors

Microsoft has not identified any mitigating factors for these vulnerabilities.

Workarounds

Microsoft has not identified any workarounds for these vulnerabilities.

Security Update Deployment

For Security Update Deployment information, see the Microsoft Knowledge Base article referenced here in the Executive Summary.

Acknowledgments

Microsoft recognizes the efforts of those in the security community who help us protect customers through coordinated vulnerability disclosure. See Acknowledgments for more information.

Disclaimer

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions

  • V1.0 (May 12, 2015): Bulletin published.
  • V2.0 (May 19, 2015): Bulletin revised to announce the release of the Microsoft Office for Mac 14.5.1 update. The release addresses a potential issue with Microsoft Outlook for Mac when customers install the Microsoft Office for Mac 14.5.0 update. Customers who have not already installed the 14.5.0 update should install the 14.5.1 update to be fully protected from this vulnerability. To avoid the possibility of future issues with Microsoft Outlook for Mac, Microsoft recommends that customers running Office for Mac software who have already successfully installed the 14.5.0 update also apply the 14.5.1 update even though they are already protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See Microsoft Knowledge Base Article 3048688 for more information.
  • V3.0 (June 9, 2015): To address issues with the security updates for all affected Microsoft Office 2010 software, Microsoft re-released MS15-046 to comprehensively address CVE-2015-1682. Microsoft recommends that customers running affected Office 2010 software should install the security updates released with this bulletin revision to be fully protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See Microsoft Knowledge Base Article 3057181 for more information and download links.
  • V4.0 (October 13, 2015): Revised bulletin to announce the availability of a new update (3085544) for Microsoft Office 2007 that addresses issues with the previously-released update (2965282). Customers running Microsoft Office 2007 are encouraged to install update 3085544 at the earliest opportunity to be fully protected from the vulnerability discussed in this bulletin. Customers running other Microsoft Office software do not need to take any action. See Microsoft Knowledge Base Article 3085544 for more information and download links.

Page generated 2015-10-06 15:28-07:00.