Executive brief
Microsoft Office contains a memory corruption vulnerability due to a failure to properly handle Rich Text Format (RTF) files in memory. Remote attackers can exploit this by tricking a user into opening a specially crafted RTF document, leading to arbitrary code execution.
Affected products
- Microsoft Word 2007 SP3
- Microsoft Office 2010 SP2
- Microsoft Word 2010 SP2
- Microsoft Word 2013 SP1
- Microsoft Word 2013 RT SP1
- Microsoft Word for Mac 2011
- Microsoft Office Compatibility Pack SP3
- Microsoft Word Automation Services on SharePoint Server 2010 SP2
- Microsoft Word Automation Services on SharePoint Server 2013 SP1
- Microsoft Office Web Apps Server 2010 SP2
- Microsoft Office Web Apps Server 2013 SP1
Timeline
- 2015-04-14: disclosed: Initial NIST analysis and CVSS V2 assignment.
- 2015-04-14: patched: Microsoft released security bulletin MS15-033.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.