ZeroHour

CVE-2015-1642

KEVmass

Memory Corruption RCE in Microsoft Office via Crafted Documents

CISA: Microsoft Office Memory Corruption Vulnerability

CVSS
EPSS
53%p99
Published
KEV added
AI analysis

CVE-2015-1642 is a memory corruption flaw in Microsoft Office (CWE-119) that allows remote attackers to execute arbitrary code by convincing a user to open a specially crafted document. Because the corruption can be triggered simply by processing a malicious file, an attacker who succeeds gains code execution in the context of the logged-in user, with the privileges of that user on the workstation. Any organization or individual running an affected version of Microsoft Office is exposed, primarily through email attachments and documents downloaded from the web. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2022-03-03 — notably years after its 2015 disclosure — with a required action to apply vendor updates, and the ~53% EPSS score (99th percentile) indicates a high likelihood of exploitation within 30 days. Related reporting on APT28 attack evolution suggests exploitation has been observed in targeted campaigns; ransomware use is unknown, and no public proof-of-concept is cataloged.

What to do: Apply the vendor's security updates for Microsoft Office per CISA's KEV required action, using Microsoft Update or your organization's Office/patch management channel to confirm current, fully patched builds. Prioritize this KEV-listed item in patch cycles, and review endpoint telemetry for suspicious process launches following Office document opens. In the interim, caution users against opening unsolicited Office documents and consider attack-surface-reduction policies that block unsafe file types or Office child processes.

Affected
Microsoft Office
Estimated exposure
massplausibly tens to hundreds of millions of Office installations worldwide — Microsoft Office is one of the most widely deployed desktop productivity suites, with installations on the order of hundreds of millions of devices, though actual risk depends on users opening untrusted documents.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Office
Weakness
CWE-119

In the news