Executive brief
Microsoft Office products are vulnerable to memory corruption when processing specially crafted documents. A remote attacker can exploit this to execute arbitrary code or cause a denial of service via an out-of-bounds write (CWE-787).
Affected products
- Microsoft PowerPoint 2007 SP3
- Microsoft Word 2007 SP3
- Microsoft PowerPoint 2010 SP2
- Microsoft Word 2010 SP2
- Microsoft PowerPoint 2013 SP1
- Microsoft Word 2013 SP1
- Microsoft PowerPoint 2013 RT SP1
- Microsoft Office 2011 for Mac
- Microsoft Excel Viewer 2007 SP3
- Microsoft Office Compatibility Pack SP3
Timeline
- 2015-07-14: disclosed: Initial Microsoft Security Bulletin MS15-070 published
- 2015-07-14: patched: Security updates released by Microsoft
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog