E15-49u01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
68
Year:
2015
Description
This strike exploits a memory corruption vulnerability in Microsoft Word.
The vulnerability is due to incorrect handling of numbering elements within a .docx file.
By enticing a victim to open a specially crafted Microsoft Word .docx file, an attacker could execute arbitrary code on the victim system.
CVE
References
http://www.zerodayinitiative.com/advisories/ZDI-15-132/