CVE-2015-2545
KEVmassMalformed EPS Image RCE in Microsoft Office
CISA: Microsoft Office Malformed EPS File Vulnerability
Microsoft Office fails to properly validate Encapsulated PostScript (EPS) images embedded in documents (CWE-20, improper input validation), and processing a specially crafted EPS image can allow arbitrary code execution. The flaw is triggered when a victim opens an Office document—typically delivered via email—that contains the malicious EPS image, with no user interaction beyond opening the file. Successful exploitation gives the attacker code execution with the privileges of the logged-in user, a technique espionage groups targeting embassies, government entities and the Indian subcontinent (e.g., Patchwork, Ke3chang-related campaigns) have used to deliver backdoors such as the BADNEWS RAT. Any organization running Microsoft Office builds that lack the relevant Office updates is affected, with historically exposed populations concentrated in government and diplomatic networks using legacy Office. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) and carries a very high EPSS (~86%), indicating active exploitation despite the fix being available since 2015.
What to do: Apply the Microsoft Office security update from the September 2015 Patch Tuesday (MS15-099) or upgrade to a currently supported Office version, per the vendor instructions required by the KEV catalog, and audit environments running legacy Office builds that no longer receive routine updates. Exercise caution with emailed Office documents containing embedded EPS images and prioritize remediation for government, diplomatic and other espionage-targeted networks.
| Microsoft Office | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Office
- Weakness
- CWE-20
In the news7 stories
Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Unit 42 details Patchwork APT campaigns against the Indian subcontinent using EPS exploits and an updated BADNEWS backdoor targeting Pakistani military and nuclear interests.
Unit 42 observed the Patchwork group (also known as Dropping Elephant and Monsoon) conducting campaigns against targets in the Indian subcontinent using weaponized documents that exploit CVE-2015-2545 and CVE-2017-0261. The documents deliver an updated BADNEWS backdoor that grants attackers full control of victim machines, using dead drop resolvers on legitimate third-party websites for C2 and HTTP for communications. Lures referenced Pakistan Army promotions, the Pakistan Atomic Energy Commission and the Ministry of the Interior, and in late January 2018 the group shifted from CVE-2017-0261 to the older CVE-2015-2545.