cbcvebase.
CVE-2015-2424
published 2015-07-14

CVE-2015-2424: Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote…

PriorityP182high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
38.50%
98.4th percentile
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftexcel_viewer
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftpowerpoint
microsoftpowerpoint
microsoftword

Detection & IOCsextracted from sources · hover to see the quote

hash112c64f7c07a959a1cbff6621850a4ad
snort
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Possible CVE-2015-2424 RTF Dropping Sofacy"; flow:established,to_client; file.data; content:"D0CF11E0A1B11AE1"; nocase; content:"ffffffffff74303074"; nocase; distance:0; fast_pattern; reference:md5,112c64f7c07a959a1cbff6621800a4ad; reference:url,isightpartners.com/2015/07/microsoft-office-zero-day-cve-2015-2424-leveraged-by-tsar-team/; classtype:targeted-activity; sid:2021431; rev:3;)
bytes
D0CF11E0A1B11AE1
bytes
ffffffffff74303074
  • The exploit is delivered via a crafted RTF/Office document (OLE2 compound file format, magic bytes D0CF11E0A1B11AE1) containing the byte pattern 'ffffffffff74303074'. Network detection should inspect HTTP responses (to_client) for these two byte sequences in sequence within the file data.
  • The vulnerability was leveraged by the Tsar Team (APT28/Sofacy) threat actor group, indicating targeted/espionage activity. Detections should be treated as high-priority targeted-activity.
  • The Emerging Threats rule SID 2021431 (rev:3) covers this CVE with medium confidence and major severity. Ensure this SID is enabled in your IDS/IPS ruleset.
  • ·The Snort/Suricata rule inspects HTTP traffic only (to_client). Delivery via other protocols (e.g., email attachments, SMB) will not be caught by this rule alone.
  • ·The ET rule confidence is rated Medium, meaning false positives are possible. Tune or validate against known-good OLE2 document traffic in your environment before blocking.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.