CVE-2012-2524EPSS p97.4%

CVE-2012-2524CVE-2012-2524

microsoft / office

Description

Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."

Scoring

CVSS 9.3 ()
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS20.12% probability of exploitation · percentile 97.4% · 2026-10-10T12:00:23Z
Last modified2026-10-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.