cbcvebase.
CVE-2015-1649
published 2015-04-14

CVE-2015-1649: Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services…

PriorityP258critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
23.30%
97.5th percentile
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftoffice_web_apps
microsoftoffice_web_apps
microsoftsharepoint_server
microsoftsharepoint_server
microsoftword
microsoftword
microsoftword

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2015-1649 is triggered via RTF file rendering in the Outlook preview pane — no user click required beyond previewing the email; monitor for suspicious RTF attachments opened via Outlook preview on Office 2007/2010 targets
  • Delivery vector is a crafted Office document (RTF) sent via email as an attachment or link; flag inbound RTF files in email for inspection on unpatched Word 2007 SP3 / Office 2010 SP2 environments
  • Patch reference is MS15-033; use this bulletin identifier to verify patch status on endpoints running Word 2007 SP3, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2
  • ·Affected products span multiple Office components; ensure patching covers all listed: Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2
  • ·EMET was noted as potentially helpful against related RTF preview-pane attacks in a prior 2014 incident; no confirmed efficacy data provided for CVE-2015-1649 specifically
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.