CVE-2015-1642
KEVmassMemory Corruption RCE in Microsoft Office via Crafted Documents
CISA: Microsoft Office Memory Corruption Vulnerability
CVE-2015-1642 is a memory corruption flaw in Microsoft Office (CWE-119) that allows remote attackers to execute arbitrary code by convincing a user to open a specially crafted document. Because the corruption can be triggered simply by processing a malicious file, an attacker who succeeds gains code execution in the context of the logged-in user, with the privileges of that user on the workstation. Any organization or individual running an affected version of Microsoft Office is exposed, primarily through email attachments and documents downloaded from the web. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2022-03-03 — notably years after its 2015 disclosure — with a required action to apply vendor updates, and the ~53% EPSS score (99th percentile) indicates a high likelihood of exploitation within 30 days. Related reporting on APT28 attack evolution suggests exploitation has been observed in targeted campaigns; ransomware use is unknown, and no public proof-of-concept is cataloged.
What to do: Apply the vendor's security updates for Microsoft Office per CISA's KEV required action, using Microsoft Update or your organization's Office/patch management channel to confirm current, fully patched builds. Prioritize this KEV-listed item in patch cycles, and review endpoint telemetry for suspicious process launches following Office document opens. In the interim, caution users against opening unsolicited Office documents and consider attack-surface-reduction policies that block unsafe file types or Office child processes.
| Microsoft Office | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Office
- Weakness
- CWE-119