Junglewise Threat Intelligence

CVE-2015-2424: Microsoft PowerPoint Memory Corruption Vulnerability

CVE-2015-2424 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-03

Executive brief

Microsoft Office products are vulnerable to memory corruption when processing specially crafted documents. A remote attacker can exploit this to execute arbitrary code or cause a denial of service via an out-of-bounds write (CWE-787).

Affected products

  • Microsoft PowerPoint 2007 SP3
  • Microsoft Word 2007 SP3
  • Microsoft PowerPoint 2010 SP2
  • Microsoft Word 2010 SP2
  • Microsoft PowerPoint 2013 SP1
  • Microsoft Word 2013 SP1
  • Microsoft PowerPoint 2013 RT SP1
  • Microsoft Office 2011 for Mac
  • Microsoft Excel Viewer 2007 SP3
  • Microsoft Office Compatibility Pack SP3

Timeline

  • 2015-07-14: disclosed: Initial Microsoft Security Bulletin MS15-070 published
  • 2015-07-14: patched: Security updates released by Microsoft
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats