CVE-2015-2545highunder attack

CVE-2015-2545

Published · Updated

73Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 7.8epss 86%
from disclosure to weapon
Published on NVDSep 9
CISA KEV+2367d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-03-24

Apply updates per vendor instructions.

In short

Microsoft Office versions 2007 through 2013 can be exploited through specially crafted EPS image files, allowing attackers to run malicious code on your computer without your knowledge. This happens when you open a document containing a malicious image.

Technical detail

A remote code execution vulnerability in Microsoft Office (2007 SP3 through 2013 RT SP1) via malformed EPS (Encapsulated PostScript) image parsing. The attack vector is document-based; an attacker can craft a malicious EPS file embedded in an Office document, which executes arbitrary code in the context of the Office application when processed, bypassing existing security controls.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a