RULE(RULE ID:316480)

Rule General Information
Release Date: 2015-12-08
Rule Name: FILE-OFFICE Microsoft Office File Modification Password Use after Free Vulnerability (CVE-2015-1683)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS15-046
SecurityTrackerID:1032295
Solutions
Microsoft has released a patch MS15-046 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS15-046