RULE(RULE ID:316424)

Rule General Information
Release Date: 2015-09-03
Rule Name: FILE-OFFICE Microsoft Office Word Use after Free Vulnerability -2 (CVE-2015-1650)
Severity:
CVE ID:
Rule Protection Details
Description: Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS15-033
SecurityTrackerID:1032104
Solutions
Microsoft has released a patch MS15-033 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS15-033