Vulnerability record · CVE-2015-1642 · published 15 August 2015
CVE-2015-1642: Microsoft Office memory corruption allows remote code execution
Microsoft · Office
Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 contain an out-of-bounds write (CWE-787) that lets a remote attacker execute arbitrary code through a crafted document. The flaw is a memory corruption issue in document parsing, so opening a malicious file can compromise the host. It matters because Office documents are routinely exchanged and the vulnerability is listed in CISA KEV.
Description
Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution via document open, KEV-listed, and very high EPSS, though it requires user interaction and affects older Office versions.
What it is
Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 contain an out-of-bounds write (CWE-787) that lets a remote attacker execute arbitrary code through a crafted document. The flaw is a memory corruption issue in document parsing, so opening a malicious file can compromise the host. It matters because Office documents are routinely exchanged and the vulnerability is listed in CISA KEV.
Impact
An attacker who gets a crafted document opened gains arbitrary code execution in the context of the Office process, which can lead to full system compromise.
Attack surface
Reached locally by opening a malicious document; the CVSS vector shows UI:R, so user interaction is required, and PR:N means no prior authentication is needed.
Exploitation
CVE-2015-1642 is in CISA KEV (added 2022-03-03) and has a high EPSS 30-day probability of 0.53213 (99th percentile), indicating observed exploitation and elevated risk.
What to do
- Apply the Microsoft MS15-081 security update to affected Office 2007 SP3, 2010 SP2, and 2013 SP1 installations.
- Prioritize patching systems still running these end-of-support Office versions or isolate them.
- Block or sandbox untrusted Office documents and disable macros where not required.
- Enforce attachment filtering and user awareness for unsolicited documents.
Detection
- Monitor for Office processes spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Alert on unexpected outbound network connections originating from WINWORD.EXE or EXCEL.EXE.
- Review endpoint logs for document opens followed by suspicious file writes or process creation.
- Hunt for known exploit document indicators and correlate with KEV-listed activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-1642 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Office Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securitytracker.com/id/1033239 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-081 | PatchVendor Advisory |
| https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=120 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1033239 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-081 | PatchVendor Advisory |
| https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=120 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1642 | US Government Resource |
Track CVE-2015-1642 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1642), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.