LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-1642: Microsoft Office Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-1642 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.

CVE-2015-1642 is a memory corruption vulnerability in Microsoft Office that can let a remote attacker run arbitrary code if a user opens a crafted document. It matters because Office is widely deployed on endpoints that handle untrusted files from email and the web; successful abuse can lead to full control of the affected workstation under the user’s privileges.

Defenders should treat this as a document-borne remote code execution risk in the Office suite. Confirm exact product editions, builds, and patch status against the vendor advisory rather than relying on secondary summaries.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In this class of flaw, malformed input causes the application to corrupt memory structures it uses while parsing or rendering content. An attacker crafts a document that triggers that corruption when opened or previewed in a vulnerable Office component.

Once memory is corrupted in a controllable way, the attacker can typically redirect execution to attacker-supplied code running in the context of the Office process and the logged-on user. No further exploit mechanics, specific file formats, or reliable weaponization details are provided in the given facts; treat any public proof-of-concept claims cautiously and validate behavior only in isolated lab environments against the vendor’s description.

Am I affected? How to find it in your systems

Microsoft Office commonly runs on Windows workstations, VDI/session hosts, and some servers used for document conversion or mail hygiene. Inventory every system that has Office or related viewers/converters installed.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as directed in the vendor advisory (CISA’s required action is to apply updates per vendor instructions). After deployment, verify the resulting Office build numbers match the fixed revisions.

If you can't patch immediately

Use compensating controls to lower likelihood and impact until the vendor update is installed.

If your data may have been exposed

Actively exploited document vulnerabilities are a common route to initial access and later data theft, even when ransomware use is not documented for this specific CVE. If you have indicators that crafted documents were opened on unpatched systems, follow your incident-response process: isolate hosts, preserve memory and disk evidence, rotate credentials accessible from those hosts, and hunt for persistence and lateral movement.

As a quick personal check, you can run a free exposure scan of your email address against known breach data to see whether your credentials have appeared in prior public dumps, then force password changes and enable phishing-resistant MFA where supported.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities