CVE-2015-2545 is a critical remote code execution vulnerability affecting Microsoft Office 2007, 2010, and 2013 versions, allowing attackers to execute arbitrary code via a crafted EPS image. This vulnerability has a high CVSS score of 7.8, indicating a severe risk with high impact on confidentiality, integrity, and availability, requiring user interaction to trigger. It is actively exploited in the wild, as evidenced by its inclusion in CISA's KEV catalog and numerous reports of APT groups leveraging it. Despite the lack of public Metasploit or ExploitDB modules, the vulnerability has garnered significant community discussion and media coverage, highlighting its widespread exploitation and impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:-:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:-:*:-:*:-:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.