LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-1641: Microsoft Office Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-1641 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context…

CVE-2015-1641 is a memory corruption vulnerability in Microsoft Office that stems from improper handling of rich text format (RTF) files in memory. An attacker who successfully exploits it can achieve remote code execution in the context of the current user, which can lead to further compromise of the workstation and any resources that user can reach. IT and security teams should treat this as a high-priority Office client risk and confirm exact scope and fixes against the vendor advisory.

CISA notes that the required action is to apply updates per vendor instructions. Public detail on ransomware use is not documented for this CVE; focus on standard remote-code-execution response and hardening for the Office document-handling path.

How it works

This issue is classified under CWE-399 (resource management errors). In plain terms, Office fails to manage memory correctly when processing certain RTF content. Memory corruption of this class can let an attacker influence program control flow so that attacker-controlled code runs with the privileges of the logged-on user.

Abuse typically involves delivering a crafted RTF file—commonly as an email attachment, a downloaded document, or a file opened from a share or web location—and enticing the user to open it in a vulnerable Office application. Because execution occurs as the current user, the impact depends on that user’s rights, running security controls, and whether additional techniques are used to escalate or move laterally. Exact exploit mechanics and any proof-of-concept details are not provided here; treat any RTF-borne Office memory-corruption pattern as in-scope and verify behavior against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Office is commonly installed on end-user Windows workstations, VDI/session hosts, and some servers that process documents. Inventory every system that has Office components capable of opening or previewing RTF or related rich-text content.

How to remediate

Patch first. Apply the Microsoft updates specified for CVE-2015-1641 exactly as described in the vendor advisory and your normal change process. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Reduce the attack surface until the vendor update can be applied everywhere.

If your data may have been exposed

Actively exploited remote-code-execution flaws in desktop productivity software frequently precede broader intrusion and data theft. If you have indicators that this vulnerability was used in your environment, follow your incident-response plan: isolate affected hosts, preserve evidence, reset credentials that may have been exposed, and assess lateral movement and data access. As a general hygiene step, users and administrators can run a free exposure scan of their email addresses against known breach datasets to see whether their identities already appear in public breach collections, then prioritize password changes and MFA accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-399
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities