Vulnerability CVE-2014-6352


Published: 2014-10-22

Description:
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.

See advisories in our WLB2 database:
Topic
Author
Date
High
MS Office 2007 and 2010 OLE Arbitrary Command Execution
Abhishek
13.11.2014
High
Microsoft Windows OLE Package Manager Code Execution Through Python
Juan vazquez
14.11.2014
High
Microsoft Windows OLE Package Manager Code Execution
Juan vazquez
14.11.2014

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Microsoft -> Windows 7 
Microsoft -> Windows 8 
Microsoft -> Windows 8.1 
Microsoft -> Windows rt 
Microsoft -> Windows rt 8.1 
Microsoft -> Windows server 2008 
Microsoft -> Windows server 2012 
Microsoft -> Windows vista 

 References:
http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-risk-for-the-november-2014-security-updates.aspx
http://twitter.com/ohjeongwook/statuses/524795124270653440
http://www.securityfocus.com/bid/70690
http://www.securitytracker.com/id/1031097
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-064
https://exchange.xforce.ibmcloud.com/vulnerabilities/97714
https://technet.microsoft.com/library/security/3010060

Copyright 2024, cxsecurity.com

 

Back to Top