Back

CVE-2015-1641

HIGH CISA KEV

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."

Published: Apr 14, 2015 Modified: Apr 22, 2026
CWE-787 CWE-787

CVSS Metrics

CVSSv3
Attack Vector: LOCAL Attack Complexity: LOW Privileges Required: NONE User Interaction: REQUIRED Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products (12)

Vendor Product Version
microsoft office 2010
microsoft office_compatibility_pack -
microsoft office_web_apps 2010
microsoft office_web_apps 2013
microsoft outlook 2011
microsoft sharepoint_server 2010
microsoft sharepoint_server 2013
microsoft word 2007
microsoft word 2010
microsoft word 2011
microsoft word 2013
microsoft word 2013

GitHub Security Advisory GHSA-7p4q-fv59-h67q

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word...

Risk Scores

CVSS Score 7.8 / 10
EPSS Score 97.33%

Top 0% most likely to be exploited

Threat Score 90.4 / 100

CISA Known Exploited

Date Added: 2021-11-03
Due Date: 2022-05-03
Required Action:

Apply updates per vendor instructions.

Data Sources

NVD CISA KEV EPSS GitHub