ZeroHour

CVE-2015-2424

KEVmass

Memory Corruption RCE in Microsoft PowerPoint via Crafted Office Documents

CISA: Microsoft PowerPoint Memory Corruption Vulnerability

CVSS
EPSS
38%p98
Published
KEV added
AI analysis

CVE-2015-2424 is a memory corruption vulnerability (CWE-119) in Microsoft PowerPoint that can be exploited when the application processes a maliciously crafted Office document. An attacker must deliver the crafted file, typically via email or a downloaded document, and persuade a user to open it, at which point corrupted memory can result in arbitrary code execution or an application crash causing denial of service. Successful exploitation lets the attacker run code in the context of the current user, a common foothold for malware or ransomware delivery. Any user or organization running an unpatched, affected version of Microsoft PowerPoint is exposed; the source data does not specify exact version ranges, so defenders should follow vendor update guidance. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, and a high EPSS score (38.5% probability of exploitation within 30 days, 98th percentile) signals elevated risk, although no public proof-of-concept is known and ransomware use is unconfirmed.

What to do: Apply Microsoft's security updates for Office/PowerPoint across all endpoints per vendor instructions, prioritizing legacy and internet-reliant systems, since CISA's required action is to apply updates and specific fixed versions are not listed in this data. Reduce trigger exposure by scanning or sandboxing inbound Office attachments, keeping Protected View enabled, and monitoring for POWERPNT.EXE spawning unexpected child processes. Because the KEV listing confirms real-world exploitation, review endpoint logs for suspicious PowerPoint document-open activity or crashes.

Affected
Microsoft PowerPoint
Estimated exposure
masstens of millions of endpoints plausibly (Office runs on hundreds of millions of PCs, including many legacy, unpatched PowerPoint installs) — Estimate derived from Microsoft Office's install base of hundreds of millions of users and devices, a portion of which still run legacy PowerPoint versions left unpatched since this 2015 flaw; exact counts of vulnerable installs are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.

CISA Known Exploited Vulnerability
Affected
Microsoft PowerPoint
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
PowerPoint
Weakness
CWE-119

In the news