CVE-2015-2424
published 2015-07-14CVE-2015-2424: Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote…
PriorityP182high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
38.50%
98.4th percentile
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel_viewer | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | powerpoint | — | — |
| microsoft | powerpoint | — | — |
| microsoft | word | — | — |
Detection & IOCsextracted from sources · hover to see the quote
hash112c64f7c07a959a1cbff6621850a4ad
snort
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Possible CVE-2015-2424 RTF Dropping Sofacy"; flow:established,to_client; file.data; content:"D0CF11E0A1B11AE1"; nocase; content:"ffffffffff74303074"; nocase; distance:0; fast_pattern; reference:md5,112c64f7c07a959a1cbff6621800a4ad; reference:url,isightpartners.com/2015/07/microsoft-office-zero-day-cve-2015-2424-leveraged-by-tsar-team/; classtype:targeted-activity; sid:2021431; rev:3;)
bytes
D0CF11E0A1B11AE1
bytes
ffffffffff74303074
- →The exploit is delivered via a crafted RTF/Office document (OLE2 compound file format, magic bytes D0CF11E0A1B11AE1) containing the byte pattern 'ffffffffff74303074'. Network detection should inspect HTTP responses (to_client) for these two byte sequences in sequence within the file data.
- →The vulnerability was leveraged by the Tsar Team (APT28/Sofacy) threat actor group, indicating targeted/espionage activity. Detections should be treated as high-priority targeted-activity.
- →The Emerging Threats rule SID 2021431 (rev:3) covers this CVE with medium confidence and major severity. Ensure this SID is enabled in your IDS/IPS ruleset.
- ·The Snort/Suricata rule inspects HTTP traffic only (to_client). Delivery via other protocols (e.g., email attachments, SMB) will not be caught by this rule alone.
- ·The ET rule confidence is rated Medium, meaning false positives are possible. Tune or validate against known-good OLE2 document traffic in your environment before blocking.
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1 Office Document memory corruption (MS15-070 / Nessus ID 84739)
vuldb·2026-04-22·CVSS 8.8
CVE-2015-2424 [HIGH] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1 Office Document memory corruption (MS15-070 / Nessus ID 84739)
A vulnerability classified as critical was found in Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1. This affects an unknown part of the component Office Document Handler. Such manipulation leads to memory corruption.
This vulnerability is documented as CVE-2015-2424. The attack can be executed remotely. Additionally, an exploit exists.
Applying a patch is advised to resolve this issue.
GHSA
GHSA-rvvj-j63r-j9x4: Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow
ghsa_unreviewed·2022-05-14
CVE-2015-2424 [HIGH] CWE-119 GHSA-rvvj-j63r-j9x4: Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
VulnCheck
Microsoft PowerPoint Memory Corruption Vulnerability
vulncheck·2015·CVSS 8.8
CVE-2015-2424 [HIGH] CWE-119 Microsoft PowerPoint Memory Corruption Vulnerability
Microsoft PowerPoint Memory Corruption Vulnerability
Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
Affected: Microsoft PowerPoint
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.recordedfuture.com/russian-apt-toolkits; https://us-cert.cisa.gov/sites/default/files/publications/AR-17-20045_Enhanced_Analysis_of_GRIZZLY_STEPPE_Activity.pdf; https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://strapi.eurepoc.eu/uploads/Eu_Repo_C_APT_profile_APT_28_4856c0a0ac.pdf
R
CISA
Microsoft PowerPoint Memory Corruption Vulnerability
cisa·2022-03-03·CVSS 8.8
CVE-2015-2424 [HIGH] CWE-119 Microsoft PowerPoint Memory Corruption Vulnerability
Vulnerability: Microsoft PowerPoint Memory Corruption Vulnerability
Affected: Microsoft PowerPoint
Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-2424
Remediation Due Date: 2022-03-24
Suricata
ET MALWARE Possible CVE-2015-2424 RTF Dropping Sofacy
suricata·2015-07-17·CVSS 8.8
CVE-2015-2424 [HIGH] ET MALWARE Possible CVE-2015-2424 RTF Dropping Sofacy
ET MALWARE Possible CVE-2015-2424 RTF Dropping Sofacy
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Possible CVE-2015-2424 RTF Dropping Sofacy"; flow:established,to_client; file.data; content:"D0CF11E0A1B11AE1"; nocase; content:"ffffffffff74303074"; nocase; distance:0; fast_pattern; reference:md5,112c64f7c07a959a1cbff6621850a4ad; reference:url,isightpartners.com/2015/07/microsoft-office-zero-day-cve-2015-2424-leveraged-by-tsar-team/; classtype:targeted-activity; sid:2021431; rev:3; metadata:created_at 2015_07_17, cve CVE_2015_2424, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
No public exploits indexed.
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
Qualys
Update2: Patch Tuesday July 2015 | Qualys
blogs_qualys·2015-07-14·CVSS 9.8
[CRITICAL] Update2: Patch Tuesday July 2015 | Qualys
Update2: Microsoft released a critical bulletin MS15-078 for a font problem that affects all versions of Windows and allows Remote Code Execution. Microsoft credits Google’s Project Zero, Fireeye and TrendMicro. TrendMicro indicates that the vulnerability came out of the HackingTeam data breach. Google’s entry for the bug indicates that they are aware of exploit code avaliable in the wild, which explains Microsoft’s out-of-band release. Patch as quickly as possible.
Update : Oracle’s CPU July 2015 fixes the 0-day vulnerability CVE-2015-2590 in Java reported by Trend Micro. We recommend treating this patch with high priority. Note: if you think you cannot use new Java due to requirements for old versions, have you looked at Oracle’s deployment rulesets?
Original : When we started preparin
Qualys
Update2: Patch Tuesday July 2015 | Qualys
blogs_qualys·2015-07-14·CVSS 9.8
[CRITICAL] Update2: Patch Tuesday July 2015 | Qualys
Update2: Microsoft released a critical bulletin MS15-078 for a font problem that affects all versions of Windows and allows Remote Code Execution. Microsoft credits Google’s Project Zero, Fireeye and TrendMicro. TrendMicro indicates that the vulnerability came out of the HackingTeam data breach. Google’s entry for the bug indicates that they are aware of exploit code avaliable in the wild, which explains Microsoft’s out-of-band release. Patch as quickly as possible.
Update: Oracle’s CPU July 2015 fixes the 0-day vulnerability CVE-2015-2590 in Java reported by Trend Micro. We recommend treating this patch with high priority. Note: if you think you cannot use new Java due to requirements for old versions, have you looked at Oracle’s deployment rulesets?
Original: When we started preparing
http://www.securitytracker.com/id/1032899https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-070http://www.securitytracker.com/id/1032899https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-070https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2424
2015-07-14
Published
2022-03-03
Added to CISA KEV
Exploited in the wild