CVE-2015-1770: Microsoft Office Uninitialized Memory Use Vulnerability
Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."
Other sources
Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1770?
CVE-2015-1770 is classified as critical due to its ability to allow remote code execution.
How do I fix CVE-2015-1770?
To fix CVE-2015-1770, install the latest security updates provided by Microsoft for Office 2013 SP1 and 2013 RT SP1.
What are the risks associated with CVE-2015-1770?
The risks include unauthorized access and control of the system through malicious Office documents.
Who is affected by CVE-2015-1770?
Users of Microsoft Office 2013 SP1 and 2013 RT SP1 are affected by CVE-2015-1770.
What kind of attacks are possible with CVE-2015-1770?
CVE-2015-1770 allows attackers to execute arbitrary code remotely when a victim opens a specially crafted Office document.