peter bassill · operator
$ cve CVE-2015-0097 JSON

CVE-2015-0097 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 40.9% (pctl 99)

Patch early

A public exploit exists.

Description

Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Word Local Zone Remote Code Execution Vulnerability."

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS40.94% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-19
On CISA KEVno
Public exploityes
Published2015-03-11
Last modified2026-06-17

Affected (3)

VendorProduct
microsoftexcel
microsoftpowerpoint
microsoftword

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD