CVE-2015-2424: Microsoft PowerPoint Memory Corruption Vulnerability
Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
Other sources
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2424?
CVE-2015-2424 is rated as critical due to its potential to allow remote code execution and memory corruption.
How do I fix CVE-2015-2424?
To fix CVE-2015-2424, users should apply the latest security updates provided by Microsoft for affected versions of PowerPoint and Word.
Which Microsoft products are affected by CVE-2015-2424?
CVE-2015-2424 affects Microsoft PowerPoint and Word 2007, 2010, and 2013, among other related Office products.
What types of attacks can be executed using CVE-2015-2424?
CVE-2015-2424 can be exploited to execute arbitrary code or cause a denial of service by opening a specially crafted Office document.
Are all users of affected Microsoft software at risk from CVE-2015-2424?
Yes, all users running the impacted versions of Microsoft PowerPoint and Word who have not updated are at risk from CVE-2015-2424.