CVE-2014-6360Code Injection in Microsoft Excel

CWE-94Code Injection6 documents5 sources
Severity
9.3CRITICALNVD
EPSS
20.1%
top 4.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 14

Description

Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack allow remote attackers to execute arbitrary code via a crafted Office document, aka "Global Free Remote Code Execution in Excel Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDmicrosoft/excel2007, 2010+1

🔴Vulnerability Details

2
GHSA
GHSA-gx3p-cxm8-8h7c: Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack allow remote attackers to execute arbitrary code via a crafted Office document2022-05-14
CVEList
CVE-2014-6360: Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack allow remote attackers to execute arbitrary code via a crafted Office document2014-12-11

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday for December 2014: Light Month, Some Changes2014-12-09
Talos
Microsoft Patch Tuesday for December 2014: Light Month, Some Changes2014-12-09
Zscaler
Zscaler found Security Vulnerabilities in MS Exchange Server
CVE-2014-6360 — Code Injection in Microsoft Excel | cvebase