logo

Microsoft Office DLL Hijacking Exploit (MS15-132)

ID: 86859798-9b1a-57b9-9e99-1d1e62e0a04d

STIX ID: report--86859798-9b1a-57b9-9e99-1d1e62e0a04d

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2026-05-14

Date Updated: 2026-08-01

...
...

This report details DLL hijacking vulnerabilities in Microsoft Office (disclosed around MS15-132) that allow remote code execution by abusing how Office loads embedded OLE/COM objects; it demonstrates attack chains that combine Office's temp-file dropping and browser download behaviors (Firefox "Open With" and Chrome/Edge auto-download) to place and load attacker-controlled DLLs from the user's %TEMP% or Downloads folder, provides proof-of-concept techniques and mitigations, and links to patches and prior research.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.