CVE-2015-2378

Microsoft Excel 2007/2010 & Viewer - Untrusted Search Path DLL Hijacking

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 SP3, and Office Compatibility Pack SP3 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Microsoft Excel DLL Remote Code Execution Vulnerability."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032899

Scores

EPSS 0.0614
EPSS Percentile 92.7%

Details

Status published
Products (4)
microsoft/excel 2007 sp3
microsoft/excel 2010 sp2 (2 CPE variants)
microsoft/excel_viewer 2007 sp3
microsoft/office_compatibility_pack
Published Jul 14, 2015
Tracked Since Feb 18, 2026