CVE-2015-1770

HIGH KEV

Microsoft Office <2013 SP1-2013 RT SP1 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2015-1770 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 28, 2022.

Description

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

References (4)

Core 4
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75016
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032523
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-059

Scores

CVSS v3 8.8
EPSS 0.7967
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-03-28
VulnCheck KEV 2018-07-01
InTheWild.io 2022-03-28
ENISA EUVD EUVD-2015-1900
CWE
CWE-824
Status published
Products (1)
microsoft/office 2013 sp1 (2 CPE variants)
Published Jun 10, 2015
KEV Added Mar 28, 2022
Tracked Since Feb 18, 2026