CVE-2015-0086

Microsoft Office Word and SharePoint - Remote Code Execution via Crafted RTF Document

Title source: llm
STIX 2.1

Description

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 Gold and SP1, Word 2013 RT Gold and SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 Gold and SP1, Web Applications 2010 SP2, and Web Apps Server 2013 Gold and SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031896

Scores

EPSS 0.1345
EPSS Percentile 96.0%

Details

CWE
CWE-399
Status published
Products (10)
microsoft/office 2010 sp2 (2 CPE variants)
microsoft/office_compatibility_pack
microsoft/office_web_apps_server 2013 (2 CPE variants)
microsoft/sharepoint_server 2010 sp2
microsoft/sharepoint_server 2013 (2 CPE variants)
microsoft/web_applications 2010 sp2
microsoft/word 2007 sp3
microsoft/word 2010 sp2
microsoft/word 2013 (2 CPE variants)
microsoft/word_viewer
Published Mar 11, 2015
Tracked Since Feb 18, 2026