CVE-2015-2545
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply updates per vendor instructions.
Microsoft Office versions 2007 through 2013 can be exploited through specially crafted EPS image files, allowing attackers to run malicious code on your computer without your knowledge. This happens when you open a document containing a malicious image.
A remote code execution vulnerability in Microsoft Office (2007 SP3 through 2013 RT SP1) via malformed EPS (Encapsulated PostScript) image parsing. The attack vector is document-based; an attacker can craft a malicious EPS file embedded in an Office document, which executes arbitrary code in the context of the Office application when processed, bypassing existing security controls.
The full analysis of this CVE is available in Portuguese →