LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-1770: Microsoft Office Uninitialized Memory Use Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-1770 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.

CVE-2015-1770 is an uninitialized memory use vulnerability in Microsoft Office. A remote attacker can use a crafted Office document to execute arbitrary code on a system where a user opens or previews that file. For IT and security teams, this matters because Office is widely deployed on endpoints and the attack path is a common document-based vector that can lead to full code execution in the context of the user.

Public detail is limited to the class of flaw and the high-level impact described by CISA. Confirm exact affected products, builds, and fixes against the vendor advisory before prioritizing work.

How it works

The weakness is tracked as CWE-19 (data processing errors) and is described as uninitialized memory use in Microsoft Office. In this class of flaw, the application reads or acts on memory that has not been properly initialized before use. When a crafted Office document is processed, that condition can be abused so that attacker-controlled data influences execution flow, ultimately allowing arbitrary code to run.

Abuse typically requires the victim to open or otherwise cause Office to parse the malicious document. No further exploit mechanics, specific object types, or proof-of-concept details are provided in the given facts; treat any deeper technical claims as unconfirmed until verified against the vendor advisory and your own lab analysis. The outcome of successful exploitation is remote code execution with the privileges of the Office process and the logged-on user.

Am I affected? How to find it in your systems

Microsoft Office commonly runs on Windows endpoints (desktops, laptops, VDI) and may appear in terminal servers or other shared environments where users handle documents. Inventory every host that has Office or related viewers/components installed.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability, following the vendor instructions referenced by CISA (“Apply updates per vendor instructions”). Confirm the exact KBs or update channels (MSI, Click-to-Run, etc.) in the official advisory and deploy through your normal test-and-rollout process.

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

If your data may have been exposed

Actively exploited document vulnerabilities can lead to endpoint compromise and later data theft or ransomware, though known ransomware use is not documented for this CVE in the provided facts. If you suspect successful exploitation, follow your incident-response process: isolate affected hosts, preserve memory and disk evidence, rotate credentials accessible from those systems, and hunt for persistence and lateral movement. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-19
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities