CVE-2015-2424
KEVmassMemory Corruption RCE in Microsoft PowerPoint via Crafted Office Documents
CISA: Microsoft PowerPoint Memory Corruption Vulnerability
CVE-2015-2424 is a memory corruption vulnerability (CWE-119) in Microsoft PowerPoint that can be exploited when the application processes a maliciously crafted Office document. An attacker must deliver the crafted file, typically via email or a downloaded document, and persuade a user to open it, at which point corrupted memory can result in arbitrary code execution or an application crash causing denial of service. Successful exploitation lets the attacker run code in the context of the current user, a common foothold for malware or ransomware delivery. Any user or organization running an unpatched, affected version of Microsoft PowerPoint is exposed; the source data does not specify exact version ranges, so defenders should follow vendor update guidance. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, and a high EPSS score (38.5% probability of exploitation within 30 days, 98th percentile) signals elevated risk, although no public proof-of-concept is known and ransomware use is unconfirmed.
What to do: Apply Microsoft's security updates for Office/PowerPoint across all endpoints per vendor instructions, prioritizing legacy and internet-reliant systems, since CISA's required action is to apply updates and specific fixed versions are not listed in this data. Reduce trigger exposure by scanning or sandboxing inbound Office attachments, keeping Protected View enabled, and monitoring for POWERPNT.EXE spawning unexpected child processes. Because the KEV listing confirms real-world exploitation, review endpoint logs for suspicious PowerPoint document-open activity or crashes.
| Microsoft PowerPoint | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
- Affected
- Microsoft PowerPoint
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- PowerPoint
- Weakness
- CWE-119