CVE-2014-6361Code Injection in Microsoft Excel

CWE-94Code Injection6 documents5 sources
Severity
9.3CRITICALNVD
EPSS
20.1%
top 4.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 14

Description

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 Gold and SP1, Excel 2013 RT Gold and SP1, and Office Compatibility Pack allow remote attackers to execute arbitrary code via a crafted Office document, aka "Excel Invalid Pointer Remote Code Execution Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDmicrosoft/excel2007, 2010, 2013+2

🔴Vulnerability Details

2
GHSA
GHSA-mw2x-vrf6-rqfv: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 Gold and SP1, Excel 2013 RT Gold and SP1, and Office Compatibility Pack allow remote attackers to2022-05-14
CVEList
CVE-2014-6361: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 Gold and SP1, Excel 2013 RT Gold and SP1, and Office Compatibility Pack allow remote attackers to2014-12-11

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday for December 2014: Light Month, Some Changes2014-12-09
Talos
Microsoft Patch Tuesday for December 2014: Light Month, Some Changes2014-12-09
Zscaler
Zscaler found Security Vulnerabilities in MS Exchange Server
CVE-2014-6361 — Code Injection in Microsoft Excel | cvebase