Junglewise Threat Intelligence

CVE-2015-1770: Microsoft Office Uninitialized Memory Use Vulnerability

CVE-2015-1770 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office 2013 and 2013 RT SP1 are vulnerable to remote code execution due to uninitialized memory use when processing crafted Office documents. An attacker can exploit this by convincing a user to open a malicious file, potentially leading to full system compromise.

Affected products

  • Microsoft Office 2013 SP1
  • Microsoft Office 2013 RT SP1

Timeline

  • 2015-06-09: disclosed: NVD Published Date
  • 2015-06-09: patched: Microsoft released security bulletin MS15-059
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats