CVE-2014-0260Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Office WEB Apps

Severity
9.3CRITICALNVD
EPSS
37.2%
top 2.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateMay 14

Description

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-jcxw-cj2x-37wj: Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP22022-05-14
CVEList
CVE-2014-0260: Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP22014-01-15

🕵️Threat Intelligence

2
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability2014-01-14
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability2014-01-14
CVE-2014-0260 — Microsoft Office WEB Apps vulnerability | cvebase