Vulnerability record · CVE-2015-2545 · published 9 September 2015
CVE-2015-2545: Microsoft Office malformed EPS image remote code execution
Microsoft · Office
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 and 2013 RT SP1 fail to properly handle a crafted EPS image, allowing memory corruption that leads to arbitrary code execution. The flaw is remotely triggerable through a document containing the malicious image, making it a classic client-side Office attack. It is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Description
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with confirmed exploitation, has a very high EPSS score, and yields remote code execution through a common user action.
What it is
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 and 2013 RT SP1 fail to properly handle a crafted EPS image, allowing memory corruption that leads to arbitrary code execution. The flaw is remotely triggerable through a document containing the malicious image, making it a classic client-side Office attack. It is listed in CISA's Known Exploited Vulnerabilities catalog, so it has been used in real attacks.
Impact
An attacker who gets the crafted file opened gains code execution in the context of the logged-on user, which can mean full control of the workstation and access to that user's data and credentials. Because Office documents are commonly exchanged, a single opened file can compromise a host.
Attack surface
Reached locally through the Office application when a user opens a document containing the malformed EPS image; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N). No authentication to a remote service is needed, only the victim opening the file.
Exploitation
CISA added it to KEV on 2022-03-03 with a 2022-03-24 remediation due date, and EPSS is 0.86053 (99.7th percentile), indicating high likelihood of exploitation. Reference tags include Exploit, and no ransomware campaign use is documented.
What to do
- Apply the Microsoft MS15-099 updates for the affected Office versions immediately.
- Where patching is delayed, block or strip EPS content in email attachments and document workflows.
- Disable or restrict EPS image handling in Office where feasible and enforce Protected View and macro/ActiveX restrictions.
- Segment and harden endpoints that run legacy Office 2007/2010/2013, since these versions are past mainstream support.
- Educate users not to open unexpected Office documents, especially from external senders.
Detection
- Hunt for Office processes (WINWORD.EXE, EXCEL.EXE, POWERPNT.EXE) spawning child processes such as cmd.exe, powershell.exe or wscript.exe.
- Monitor for Office documents containing embedded EPS objects or unusual image streams, and alert on EPS parsing in document viewers.
- Review endpoint telemetry for memory corruption or crash patterns in Office when opening documents, and correlate with file download or email attachment events.
- Use the KEV due date to verify patch compliance for the affected Office builds across the estate.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-2545 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Office Malformed EPS File Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://blog.morphisec.com/exploit-bypass-emet-cve-2015-2545 | ExploitThird Party Advisory |
| http://www.securitytracker.com/id/1033488 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099 | PatchVendor Advisory |
| http://blog.morphisec.com/exploit-bypass-emet-cve-2015-2545 | ExploitThird Party Advisory |
| http://www.securitytracker.com/id/1033488 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-099 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2545 | US Government Resource |
Track CVE-2015-2545 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-2545), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.