vendor:
Microsoft Office 2010
by:
g11tch
5.5
CVSS
MEDIUM
Download and execute vulnerability
CWE
Product Name: Microsoft Office 2010
Affected Version From: ALL
Affected Version To: ALL
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP1, SP2, Windows 7
2013
MS Office 2010 Download Execute
This exploit allows an attacker to generate a meterpreter .exe and provide a link to it via the exploit. The .exe will be automatically downloaded and executed.
Mitigation:
Ensure that files downloaded from untrusted sources are not executed. Regularly update the software to the latest version.