CVE-2014-6334Code Injection in Microsoft Word

CWE-94Code Injection6 documents5 sources
Severity
9.3CRITICALNVD
EPSS
46.0%
top 2.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 11
Latest updateMay 14

Description

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Bad Index Remote Code Execution Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDmicrosoft/word2007

🔴Vulnerability Details

2
GHSA
GHSA-gx9x-c2w3-957w: Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service2022-05-14
CVEList
CVE-2014-6334: Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service2014-11-11

🕵️Threat Intelligence

3
Talos
Microsoft Update Tuesday November 2014: Fixes for 3 0-day Vulnerabilities2014-11-11
Talos
Microsoft Update Tuesday November 2014: Fixes for 3 0-day Vulnerabilities2014-11-11
Zscaler
Zscaler found Multiple Security Vulnerabilities | 11-11-2014
CVE-2014-6334 — Code Injection in Microsoft Word | cvebase