Microsoft Windows OLE Remote Code Execution Vulnerabilities
Last Update Date:
18 Nov 2014
Release Date:
12 Nov 2014
3779
Views
RISK: High Risk
TYPE: Operating Systems - Windows OS
- Windows OLE Automation Array Remote Code Execution Vulnerability
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. Microsoft received information about this vulnerability through coordinated vulnerability disclosure. When this security bulletin was issued, Microsoft had not received any information to indicate that this vulnerability had been publicly used to attack customers. This update addresses the vulnerability by modifying the way that the affected operating systems validate the use of memory when OLE objects are accessed, and by modifying the way that Internet Explorer handles objects in memory. - Windows OLE Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the context of the current user that is caused when a user downloads, or receives, and then opens a specially crafted Microsoft Office file that contains OLE objects. Microsoft first received information about this vulnerability through coordinated vulnerability disclosure. This vulnerability was first described in Microsoft Security Advisory 3010060. Microsoft is aware of limited attacks that attempt to exploit this vulnerability. This update addresses the vulnerability by modifying the way that the affected operating systems validate the use of memory when OLE objects are accessed.
Impact
- Remote Code Execution
System / Technologies affected
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
- Windows 8 and Windows 8.1
- Windows Server 2012 and Windows Server 2012 R2
- Windows RT and Windows RT 8.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS14-064
Vulnerability Identifier
Source
Related Link
Share with