← Back to CVE List
Vulnerability Intelligence Report
Microsoft PowerPoint Memory Corruption Vulnerability

CVE-2015-2424

Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:38.50%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-787 ↗CWE-787 Out-of-bounds Write

Affected Products & Versions

Vendor Product Affected Versions
microsoft excel_viewer 2007
microsoft office 2007, 2010, 2011, 2013
microsoft office_compatibility_pack all
microsoft powerpoint 2007, 2010
microsoft word 2013
microsoft word_viewer all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
38.497%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2015-03-19T00:00:00
Published2015-07-14T21:00:00
Patch Date2015-07-14
Last Updated2025-10-21T23:55:59

LINK COPIED TO CLIPBOARD