Unrated severityNVD Advisory· Published Dec 9, 2015· Updated May 6, 2026
CVE-2015-6172
CVE-2015-6172
Description
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE Vulnerability."
Affected products
7- cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
1- Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening EnterprisesSecurityWeek · May 13, 2026