CVE Feed

    Dashboard / CVE / CVE-2015-2503

    CVE-2015-2503

    Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2007 IME (Japanese) SP3, Access 2010 SP2, Excel 2010 SP2, InfoPath 2010 SP2, OneNote 2010 SP2, PowerPoint 2010 SP2, Project 2010 SP2, Publisher 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Pinyin IME 2010, Access 2013 SP1, Excel 2013 SP1, InfoPath 2013 SP1, OneNote 2013 SP1, PowerPoint 2013 SP1, Project 2013 SP1, Publisher 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, OneNote 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Access 2016, Excel 2016, OneNote 2016, PowerPoint 2016, Project 2016, Publisher 2016, Visio 2016, Word 2016, Skype for Business 2016, and Lync 2013 SP1 allow remote attackers to bypass a sandbox protection mechanism and gain privileges via a crafted web site that is accessed with Internet Explorer, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Microsoft Office Elevation of Privilege Vulnerability."

    Published:Nov 11, 2015
    Last Modified:Apr 12, 2025
    EPS:Nov 11, 2015
    EPSS Score:0.19426
    CVSS Score:9.3

    Affected Products

    Vendor
    Microsoft
    Product
    Access
    Vendor
    Microsoft
    Product
    Excel
    Vendor
    Microsoft
    Product
    Infopath
    Vendor
    Microsoft
    Product
    Lync
    Vendor
    Microsoft
    Product
    Office 2007 Ime
    Vendor
    Microsoft
    Product
    Onenote
    Vendor
    Microsoft
    Product
    Pinyin Ime
    Vendor
    Microsoft
    Product
    Powerpoint
    Vendor
    Microsoft
    Product
    Project
    Vendor
    Microsoft
    Product
    Project Server
    Vendor
    Microsoft
    Product
    Publisher
    Vendor
    Microsoft
    Product
    Skype For Business
    Vendor
    Microsoft
    Product
    Visio
    Vendor
    Microsoft
    Product
    Word

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High