← Vulnerability feed

Vulnerability record · CVE-2015-1641 · published 14 April 2015

CVE-2015-1641: Microsoft Office Word RTF out-of-bounds write memory corruption

Microsoft · Office

Microsoft Word and related Office components (Word 2007/2010/2013, Word for Mac 2011, Office Compatibility Pack, Word Automation Services, Office Web Apps) contain an out-of-bounds write (CWE-787) that is triggered when parsing a crafted RTF document. Successful exploitation allows arbitrary code execution in the context of the opening user. The flaw is old but remains actively exploited and is listed in CISA KEV, so unpatched Office installations are still at real risk.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 97% · top 0.1% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 9.3
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

high priorityThe vulnerability is in CISA KEV with a very high EPSS score and allows remote code execution, though exploitation requires user interaction to open a crafted document.

What it is

Microsoft Word and related Office components (Word 2007/2010/2013, Word for Mac 2011, Office Compatibility Pack, Word Automation Services, Office Web Apps) contain an out-of-bounds write (CWE-787) that is triggered when parsing a crafted RTF document. Successful exploitation allows arbitrary code execution in the context of the opening user. The flaw is old but remains actively exploited and is listed in CISA KEV, so unpatched Office installations are still at real risk.

Impact

An attacker who gets a victim to open a malicious RTF document can execute arbitrary code with the privileges of the logged-on user, potentially leading to full system compromise.

Attack surface

Reached locally by opening a crafted RTF file in a vulnerable Office product; the CVSS vector (AV:L/UI:R) indicates user interaction is required and no privileges are needed. No authentication is required, but the victim must open or preview the malicious document.

Exploitation

CVE-2015-1641 is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.96758 (99.884th percentile), indicating observed exploitation and very high likelihood of attempted exploitation. No ransomware campaign use is documented in the record.

What to do

  • Apply the Microsoft MS15-033 security update to all affected Office, Word, SharePoint, and Office Web Apps installations.
  • Disable or restrict opening of untrusted RTF documents and block RTF content in email attachments where business needs allow.
  • Enable Microsoft Office Protected View and File Block settings for legacy formats to reduce exposure to malicious documents.
  • Keep Office and Windows fully patched and remove or upgrade end-of-life products such as Office 2007, Office 2010, and Word for Mac 2011.
  • Segment and monitor systems that must process untrusted documents, and restrict user privileges to limit post-exploitation impact.

Detection

  • Monitor for Office processes (WINWORD.EXE, OUTLOOK.EXE) spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
  • Hunt for RTF files with embedded objects or unusual OLE structures delivered via email or downloaded from the web.
  • Review endpoint telemetry for suspicious file writes or memory corruption crashes in Office applications.
  • Alert on known exploitation indicators and correlate with CISA KEV guidance for CVE-2015-1641.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-1641 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-1641 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-20963Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 30%analysed9.8CVE-2025-53770Microsoft SharePoint Server deserialization RCE under active exploitationOn-premises Microsoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker run code on the server. Microsoft st…KEVEPSS 100%analysed9.8CVE-2023-29357Microsoft SharePoint Server elevation of privilege via authentication bypassCVE-2023-29357 is a critical elevation of privilege flaw in Microsoft SharePoint Server. The CVSS vector shows it is network reachable with no privil…KEVEPSS 100%analysed9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed9.8CVE-2019-0604Microsoft SharePoint application package markup validation RCEMicrosoft SharePoint fails to validate the source markup of an application package, allowing crafted packages to execute code on the server. This is …KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2015-1641), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.