Skip to content

CVE-2015-1641

Out-of-bounds Write — is CVE-2015-1641real, exploitable, or a false positive? Here's the community ground truth.

High · CVSS 7.8EPSS 97.3%CISA KEVCWE-787 · Out-of-bounds Write

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."

Published

Embed this verdict
TruePositive verdict for CVE-2015-1641
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2015-1641/badge.svg)](https://www.truepositive.app/cve/CVE-2015-1641)
HTML
<a href="https://www.truepositive.app/cve/CVE-2015-1641"><img src="https://www.truepositive.app/cve/CVE-2015-1641/badge.svg" alt="TruePositive verdict for CVE-2015-1641"></a>

Live badge — updates automatically as the community verdict changes.

Community ground truth

Community verdict

3 verdicts
Not a real issue

Includes TruePositive's curated baseline from public sources — community verdicts accrue on top.

to add your verdict.

Community real-world severity: High (High 3) — CVSS base score 7.8

In line with its CVSS base score.

Field notes & remediation

Verdicts are the quick signal — notes are the evidence and fixes behind them.

  • 0
    Field note · Priya NairCurated

    Confirmed exploited in the wild — listed in the CISA KEV catalog (added 2021-11-03). Treat as real and prioritize patching over triage.

Same weaknessCWE-787 · Out-of-bounds Write.