Microsoft Windows OLE Object Handling Remote Code Execution Vulnerability
RISK: Extremely High Risk
TYPE: Operating Systems - Windows OS
A vulnerability has been identified in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an unspecified error when handling OLE objects embedded within Microsoft Office files and can be exploited to execute arbitrary code.
Note:
No patch is available currently, but the vendor has provided workarounds.
Reportedly, this vulnerability is currently being exploited in limited, targeted attacks.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Windows 7
- Microsoft Windows 8
- Microsoft Windows 8.1
- Microsoft Windows RT
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2008
- Microsoft Windows Server 2012
- Microsoft Windows Vista
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has provided workarounds, for details please refer to the below link:
https://technet.microsoft.com/en-us/library/security/3010060#ID0EPG
Vulnerability Identifier
Source
Related Link
Share with