Site icon The Mac Security Blog

Microsoft Office for Mac 14.5.7 Update Patches Remote Code Execution Flaws

Microsoft has released Office for Mac 14.5.7 as an update that patches two remote code execution flaws affecting Microsoft Excel for Mac 2011.

“The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An attacker who successfully exploited the vulnerabilities could run arbitrary code in the context of the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative rights,” says the Microsoft security team.

The vulnerabilities patched in this update are described as follows:

The Microsoft security team addressed the vulnerabilities by correcting how Office handles objects in memory.

The Office for Mac 2011 14.5.7 update can be obtained by using the Microsoft AutoUpdate for Mac, or you can visit the Microsoft Download Center to download the Office for Mac 14.5.7 update (113.4 MB).

Share this: