ZeroHour

CVE-2015-1770

KEVmass

Uninitialized Memory Use RCE in Microsoft Office

CISA: Microsoft Office Uninitialized Memory Use Vulnerability

CVSS
EPSS
35%p98
Published
KEV added
AI analysis

CVE-2015-1770 is a use of uninitialized memory flaw in Microsoft Office that can lead to remote code execution. It is triggered when a user is convinced to open a crafted Office document, causing Office to process uninitialized memory in a way an attacker can leverage. A successful attacker gains the ability to execute arbitrary code in the context of the current user. Any environment running affected Microsoft Office builds, particularly legacy or unpatched installations, is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), indicating known in-the-wild exploitation; EPSS estimates a 35.1% probability of exploitation in the next 30 days (98th percentile), and no public PoC is known.

What to do: Apply Microsoft's updates for CVE-2015-1770 across all Office installations per vendor instructions, prioritizing systems handling untrusted documents given the KEV listing. Audit legacy or infrequently updated Office builds with patch inventories to confirm the fix is present. Until patched, have users avoid opening Office files from untrusted sources and consider hardening or disabling document preview and auto-open flows.

Affected
Microsoft Office
Estimated exposure
masshundreds of millions of Office users worldwide; number of currently unpatched installs unknown — Microsoft Office is the dominant desktop office suite with hundreds of millions of users, though the share of installations that never received the 2015 fix cannot be determined from the available data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Office
Weakness
CWE-19

In the news