cbcvebase.
CVE-2014-1761
published 2014-03-25

CVE-2014-1761: Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation…

PriorityP187high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-08-15
Exploited in the wild
EPSS
77.46%
99.5th percentile
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.

Affected

9 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftoffice_web_apps
microsoftoffice_web_apps_server
microsoftsharepoint_server
microsoftsharepoint_server
microsoftword
microsoftword
microsoftword
microsoftword

Detection & IOCsextracted from sources · hover to see the quote

hash7e031a04e570cddda907d0b4b7af19ce60dc481394dfb3813796ce0e6d079305
snort
SID 24974
snort
SID 24975
snort
SID 30497
snort
SID 30498
snort
SID 30499
snort
SID 30500
snort
SID 30501
snort
SID 30502
snort
SID 30508
snort
SID 30509
  • Detect RTF files with invalid 'listoverridecount' values — only legal values are 0, 1, or 9; any other value is indicative of CVE-2014-1761 exploitation.
  • ·The ClamAV signature for CVE-2012-2539/CVE-2014-1761 was temporarily converted to a PUA (Potentially Unwanted Application) signature due to false positives from legitimate RTF generators that produce non-standard listoverridecount values; tuning may be required.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.