VYPR
Unrated severityNVD Advisory· Published Dec 9, 2015· Updated May 6, 2026

CVE-2015-6172

CVE-2015-6172

Description

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE Vulnerability."

Affected products

7
  • Microsoft/Office2 versions
    cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:*
  • cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*
  • Microsoft/Word4 versions
    cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

1