CVE-2012-2524: Microsoft Office

High severity, CVSS 9.3. EPSS: 20.1% chance of exploitation in the next 30 days.

Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."

Affected products

  • Microsoft Office: version 2007 only; version 2010 only

Published 2012-08-15. Last modified 2026-10-09.