EXPOSURES › CVE-2015-1641
CVE-2015-1641
HIGH ⌖ ON CISA KEV · EXPLOITEDA memory corruption flaw in Microsoft Office allowed remote code execution when processing rich text format files.
This vulnerability enabled attackers to execute arbitrary code on a victim's system by opening a malicious .rtf file, directly impacting DIB organizations that rely on Office for document handling. The failure stems from improper memory management, a classic unpatched or delayed-patch scenario that DIBs must vigilantly monitor and patch to prevent compromise.
Shame score — A memory corruption vulnerability in a ubiquitous productivity tool that enables remote code execution represents a severe, avoidable exposure that DIBs must actively patch and monitor.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.
"Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory."
"JP Morgan Chase Data Breached: Years-Long JP Morgan Chase Software Flaw Results in Unauthorized Access of Sensitive Financial Information"
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |