Junglewise Threat Intelligence

CVE-2015-1641: Microsoft Office Memory Corruption Vulnerability

CVE-2015-1641 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office contains a memory corruption vulnerability due to a failure to properly handle Rich Text Format (RTF) files in memory. Remote attackers can exploit this by tricking a user into opening a specially crafted RTF document, leading to arbitrary code execution.

Affected products

  • Microsoft Word 2007 SP3
  • Microsoft Office 2010 SP2
  • Microsoft Word 2010 SP2
  • Microsoft Word 2013 SP1
  • Microsoft Word 2013 RT SP1
  • Microsoft Word for Mac 2011
  • Microsoft Office Compatibility Pack SP3
  • Microsoft Word Automation Services on SharePoint Server 2010 SP2
  • Microsoft Word Automation Services on SharePoint Server 2013 SP1
  • Microsoft Office Web Apps Server 2010 SP2
  • Microsoft Office Web Apps Server 2013 SP1

Timeline

  • 2015-04-14: disclosed: Initial NIST analysis and CVSS V2 assignment.
  • 2015-04-14: patched: Microsoft released security bulletin MS15-033.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats