Junglewise Threat Intelligence

CVE-2015-2545: Microsoft Office Malformed EPS File Vulnerability

CVE-2015-2545 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Office, Microsoft Office 2016. Vendors: Microsoft.

Executive brief

Microsoft Office allows remote attackers to execute arbitrary code via a specially crafted Encapsulated PostScript (EPS) image. The vulnerability stems from improper handling of malformed EPS files, leading to memory corruption.

Affected products

  • Microsoft Office 2007 SP3
  • Microsoft Office 2010 SP2
  • Microsoft Office 2013 SP1
  • Microsoft Office 2013 RT SP1
  • Microsoft Office 2016

Timeline

  • 2015-09-08: patched: Microsoft released security bulletin MS15-099.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats