SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2015-2424

Microsoft PowerPoint Memory Corruption Vulnerability

KEVHIGH 8.8EPSS 38.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
38.50% probability · 98th percentile
CISA KEV
Listed 3 March 2022 · due 24 March 2022
Weakness
CWE-787
Affected
microsoft/excel viewer · microsoft/office · microsoft/office compatibility pack · microsoft/powerpoint · microsoft/word · microsoft/word viewer
Source
secure@microsoft.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2015-2424

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.