EXPOSURES › CVE-2015-2545
CVE-2015-2545
HIGH ⌖ ON CISA KEV · EXPLOITEDA malformed EPS file in Microsoft Office allowed remote attackers to execute arbitrary code, and the vulnerability was actively exploited in the wild.
Microsoft Office failed to properly validate malformed EPS image files, enabling remote code execution. DIB organizations must ensure all Office products are patched and monitored for KEV-listed exploits, as this vulnerability was actively exploited in the wild and could lead to ransomware or data breaches if unpatched.
Shame score — A known vulnerability in a widely deployed product was actively exploited in the wild, indicating a failure to patch or mitigate a critical flaw that could lead to severe compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |