CVE-2015-1770: Microsoft Office Uninitialized Memory Use Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-03-28. EPSS: 35% chance of exploitation in the next 30 days.
Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."
Affected products
- Microsoft Office: version 2013 only
Published 2015-06-10. Last modified 2026-06-17.