Skip to content
COOEY

EXPOSURES › CVE-2015-1641

CVE-2015-1641

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-1641 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

A memory corruption flaw in Microsoft Office allowed remote code execution when processing rich text format files.

This vulnerability enabled attackers to execute arbitrary code on a victim's system by opening a malicious .rtf file, directly impacting DIB organizations that rely on Office for document handling. The failure stems from improper memory management, a classic unpatched or delayed-patch scenario that DIBs must vigilantly monitor and patch to prevent compromise.

Shame score — A memory corruption vulnerability in a ubiquitous productivity tool that enables remote code execution represents a severe, avoidable exposure that DIBs must actively patch and monitor.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Widespread condemnation due to the severity of the vulnerability and its potential for remote code execution.
cooey ↗ severe-fallout -0.70
Neutral reporting, highlighting the technical details of the vulnerability.
"Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory."
recentbreaches.com ↗ severe-fallout +0.00
Neutral listing, part of a larger database of breaches.
cvedb.shodan.io ↗ severe-fallout +0.00
Neutral listing, part of a larger API documentation.
dailysecurityreview.com ↗ severe-fallout +0.00
Neutral reporting, focusing on the breach itself, not Microsoft's role.
"JP Morgan Chase Data Breached: Years-Long JP Morgan Chase Software Flaw Results in Unauthorized Access of Sensitive Financial Information"
www.cvefind.com ↗ severe-fallout +0.00
Neutral listing, part of a larger database of vulnerabilities.
cvedb.shodan.io ↗ severe-fallout +0.00
Neutral listing, part of a larger API documentation.
app.opencve.io ↗ severe-fallout +0.00
Neutral listing, part of a larger database of vulnerabilities.
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized