Vulnerability record · CVE-2015-1641 · published 14 April 2015
CVE-2015-1641: Microsoft Office Word RTF out-of-bounds write memory corruption
Microsoft · Office
Microsoft Word and related Office components (Word 2007/2010/2013, Word for Mac 2011, Office Compatibility Pack, Word Automation Services, Office Web Apps) contain an out-of-bounds write (CWE-787) that is triggered when parsing a crafted RTF document. Successful exploitation allows arbitrary code execution in the context of the opening user. The flaw is old but remains actively exploited and is listed in CISA KEV, so unpatched Office installations are still at real risk.
Description
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe vulnerability is in CISA KEV with a very high EPSS score and allows remote code execution, though exploitation requires user interaction to open a crafted document.
What it is
Microsoft Word and related Office components (Word 2007/2010/2013, Word for Mac 2011, Office Compatibility Pack, Word Automation Services, Office Web Apps) contain an out-of-bounds write (CWE-787) that is triggered when parsing a crafted RTF document. Successful exploitation allows arbitrary code execution in the context of the opening user. The flaw is old but remains actively exploited and is listed in CISA KEV, so unpatched Office installations are still at real risk.
Impact
An attacker who gets a victim to open a malicious RTF document can execute arbitrary code with the privileges of the logged-on user, potentially leading to full system compromise.
Attack surface
Reached locally by opening a crafted RTF file in a vulnerable Office product; the CVSS vector (AV:L/UI:R) indicates user interaction is required and no privileges are needed. No authentication is required, but the victim must open or preview the malicious document.
Exploitation
CVE-2015-1641 is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.96758 (99.884th percentile), indicating observed exploitation and very high likelihood of attempted exploitation. No ransomware campaign use is documented in the record.
What to do
- Apply the Microsoft MS15-033 security update to all affected Office, Word, SharePoint, and Office Web Apps installations.
- Disable or restrict opening of untrusted RTF documents and block RTF content in email attachments where business needs allow.
- Enable Microsoft Office Protected View and File Block settings for legacy formats to reduce exposure to malicious documents.
- Keep Office and Windows fully patched and remove or upgrade end-of-life products such as Office 2007, Office 2010, and Word for Mac 2011.
- Segment and monitor systems that must process untrusted documents, and restrict user privileges to limit post-exploitation impact.
Detection
- Monitor for Office processes (WINWORD.EXE, OUTLOOK.EXE) spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Hunt for RTF files with embedded objects or unusual OLE structures delivered via email or downloaded from the web.
- Review endpoint telemetry for suspicious file writes or memory corruption crashes in Office applications.
- Alert on known exploitation indicators and correlate with CISA KEV guidance for CVE-2015-1641.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-1641 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/73995 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1032104 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-033 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/73995 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1032104 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-033 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1641 | US Government Resource |
Track CVE-2015-1641 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1641), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.