Microsoft Office Remote Code Execution Vulnerability
Last Update Date:
18 Nov 2014
Release Date:
12 Nov 2014
3615
Views
RISK: Medium Risk
TYPE: Clients - Productivity Products
- Microsoft Office Double Delete Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the context of the current user that is caused when Microsoft Word does not properly handle objects in memory while parsing specially crafted Office files. Microsoft received information about the vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this vulnerability had been publicly used to attack customers. The security update addresses the vulnerability by correcting how Microsoft Office parses specially crafted files. - Microsoft Office Bad Index Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the context of the current user that is caused when Microsoft Word improperly handles objects in memory while parsing specially crafted Office files. This could corrupt system memory in such a way as to allow an attacker to execute arbitrary code. Microsoft received information about these vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this vulnerability had been publicly used to attack customers. The security update addresses the vulnerability by correcting how Microsoft Office parses specially crafted files. - Microsoft Office Invalid Pointer Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the context of the local user that is caused when Microsoft Word does not properly handle objects in memory while parsing specially crafted Office files. This could corrupt system memory in such a way as to allow an attacker to execute arbitrary code. Microsoft received information about these vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this vulnerability had been publicly used to attack customers. The security update addresses the vulnerability by correcting how Microsoft Office parses specially crafted files.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Office 2007 Service Pack 3
- Microsoft Word Viewer
- Microsoft Office Compatibility Pack Service Pack 3
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS14-069
Vulnerability Identifier
Source
Related Link
Share with