EXPOSURES › CVE-2015-1642
CVE-2015-1642
HIGH ⌖ ON CISA KEV · EXPLOITEDA memory corruption flaw in Microsoft Office allowed remote attackers to execute arbitrary code via a crafted document.
This unpatched vulnerability was actively exploited in the wild, enabling remote code execution without requiring user interaction beyond opening a malicious file. DIB organizations must ensure all Office applications are patched and restricted, as this represents a high-embarrassment failure due to its long-standing presence in the KEV catalog and avoidable nature of memory corruption bugs.
Shame score — The vulnerability remained unpatched for years and was actively exploited in the wild, demonstrating severe negligence in patch management and vulnerability handling.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |