SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-2470

Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 2011, and Word Viewer allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Integer Underflow…

HIGH 9.3EPSS 26.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 26.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 2011, and Word Viewer allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Integer Underflow Vulnerability."

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
26.86% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-189
Affected
microsoft/office · microsoft/word · microsoft/word viewer
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.