Disclosure summary
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted template, aka "Microsoft Office Remote Code Execution Vulnerability."
Source-reported weakness categories
CWE-20
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2015-2466
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| microsoft | office | 2007 |
| microsoft | office | 2010 |
| microsoft | office | 2013 |
Original records & references
PUBLISHED 2015-08-14T20:59:25-04:00
MODIFIED 2026-10-09T15:16:40-04:00
INGESTED 2026-10-10T20:50:18-04:00