CVE detail
CVE-2015-2545
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.3 · diversity 13.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
16 source links · newest first
- Patchwork Cyberspies Update the Badnews BackdoorSecurityWeek
Recent infection campaigns conducted by the Patchwork cyberespionage group have revealed the use of an EPS exploit and an updated backdoor, Palo Alto Networks reports.
newswww.securityweek.comMar 13, 2018, 3:22 AM Unit 42 observes the Patchwork group continuing to use weaponized legitimate documents to deliver their updated BADNEWS payload.
vendorunit42.paloaltonetworks.comMar 7, 2018, 3:00 AMAdobe’s Flash Player might be the most targeted product when criminal exploit kits are involved, but Microsoft products such as Office, Windows and Internet Explorer take center stage when Russian advanced persistent threat (APT) groups are involved.
newswww.securityweek.comAug 5, 2016, 2:10 PM- Patchwork Threat Actor Expands Target ListSecurityWeek
The India-linked threat actor known as Patchwork or Dropping Elephant is targeting more than just government-associated organizations, Symantec researchers say.
newswww.securityweek.comJul 26, 2016, 11:26 AM Most attacks that are targeting vulnerabilities in Microsoft Office to compromise victims’ systems are currently leveraging two security issues that were discovered last year, SophosLabs researchers warn.
newswww.securityweek.comJul 19, 2016, 8:32 PM- NetTraveler APT still targets European and Russian interestsSecurity Affairs
Security experts from ProofPoint have spotted a new campaign operated by the APT Group NetTraveler that is targeting Russian and European organizations. NetTraveler is an ATP group first spotted by Kaspersky in 2013, when researchers discovered an espionage activity against over 350 high profile victims from 40 countries. The name of the operation derives from the malicious […]
newssecurityaffairs.comJul 9, 2016, 10:23 AM APT Group Uses NetTraveler to Spy on Russian, European Victims
newswww.securityweek.comJul 8, 2016, 12:01 PM- Old Office Flaw Still Exploited in Many AttacksSecurityWeek
An Office vulnerability patched by Microsoft more than four years ago continues to be exploited in many attacks where malicious actors attempt to deliver malware using specially crafted documents.
newswww.securityweek.comJul 5, 2016, 12:57 PM An Office vulnerability patched by Microsoft last year has been exploited by several advanced persistent threat (APT) actors in operations aimed at organizations in Asia, Kaspersky Lab’s Global Research and Analysis Team reported on Wednesday.
newswww.securityweek.comMay 25, 2016, 6:41 PMSecurity experts from PaloAlto Networks collected evidence that the Operation Ke3chang discovered by FireEye in 2013 is still ongoing. Back in 2013, the security researchers at FireEye spotted a group of China-Linked hackers that conducted an espionage campaign on foreign affairs ministries in Europe. The campaign was named ‘Operation Ke3chang,’ now threat actors behind the […]
newssecurityaffairs.comMay 24, 2016, 5:59 AMA threat group first analyzed more than two years ago has continued to improve its malware arsenal and was recently observed targeting personnel at Indian embassies worldwide.
newswww.securityweek.comMay 23, 2016, 7:36 PMIntroduction Little has been published on the threat actors responsible for Operation Ke3chang since the report was released more than two years ago. However, Unit 42 has recently discovered the actors have continued to evolve their custom malware arsenal. We’ve discovered a new malware family we’ve named TidePool. It has strong behavioral ties to Ke3chang
vendorunit42.paloaltonetworks.comMay 22, 2016, 3:00 PMMalware writers have always sought to develop feature-rich, easy to use tools that are also somewhat hard to detect via both host- and network-based detection systems. For many years, one of the go-to families of malware used by both less-skilled and advanced actors has been the Poison Ivy (aka PIVY) RAT. Poison Ivy has a
vendorunit42.paloaltonetworks.comApr 22, 2016, 2:45 AMProofpoint has collected evidence of new Carbanak group campaigns.The hackers are targeting banks in the Middle East, the United States and other countries. Security researchers at Proofpoint firm sustain to have collected evidence of new Carbanak group campaigns. This time the hackers are targeting banks in the Middle East, the United States and other countries. Last year, Kaspersky […]
newssecurityaffairs.comMar 17, 2016, 7:45 AMResearchers at security firm Proofpoint have discovered what they believe to be new Carbanak campaigns aimed at organizations in the Middle East, the United States and other countries.
newswww.securityweek.comMar 16, 2016, 11:03 AMMicrosoft released twelve patches fixing over 50 vulnerabilities in Internet Explorer, Microsoft Edge, Active Directory Service, Microsoft Graphics Component, Windows Journal, Microsoft Office, Windows Media Center, .NET Framework, Windows Task Management, Microsoft Exchange Server, Skype for Business Server and Lync Server, and Windows Hyper-V.Of these patches and updates, those for IE, Edge, MS Graphics Component, Windows Journal and Microsoft Office are the most critical ones as they can lead to malicious code execution, and should … More →
newswww.helpnetsecurity.comSep 9, 2015, 4:49 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-55054CVSS 6.5 · Medium
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- CVE-2026-47293CVSS 7.0 · High
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
- CVE-2026-42832CVSS 7.7 · High
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-42831CVSS 7.8 · High
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-40421CVSS 4.3 · Medium
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-40420CVSS 8.8 · High
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.