cbcvebase.
CVE-2015-0097
published 2015-03-11

CVE-2015-0097: Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute…

PriorityP267critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
40.94%
98.5th percentile
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Word Local Zone Remote Code Execution Vulnerability."

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftpowerpoint
microsoftpowerpoint
microsoftword
microsoftword

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/37657.zip
filename.wps
filename.doc
filename.RTF
  • Detect Office documents (.wps, .doc, .rtf) with a trailing space in the file extension, which is used to trigger the vulnerability.
  • Monitor Microsoft Word, Excel, or PowerPoint 2007 processes spawning child processes or executing script code, as the exploit runs HTML/script in the Local Machine Zone of Internet Explorer.
  • Alert on Office applications (Word/Excel/PowerPoint 2007) opening or referencing .wps (Works document) files as HTML, which is the core exploitation vector.
  • ·Affected versions are specifically Office 2007 SP3 and Office 2010 SP2 (Word, Excel, PowerPoint); detection logic should be scoped to these versions.
  • ·The exploit was tested on Windows XP, 2003, Vista, 2008, 7, 8, and 8.1; detections targeting process lineage or zone execution may need tuning per OS version.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.