CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS14-017 | Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2949660) | Microsoft Office | Critical | 09-04-2014 |
Technical Information
Brief overview of the risk:
This security update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities in Microsoft Office. The most severe of these vulnerabilities could allow remote code execution if a specially crafted file is opened or previewed in an affected version of Microsoft Office software.
Detailed Information on the risk:
A remote code execution vulnerability exists in the way that affected Microsoft Office software converts specially crafted files. An attacker who successfully exploited this vulnerability could run arbitrary code as the current user.
Further information on this exploit is available at : MS14-017
Affected Software
Microsoft Office 2003 Service Pack 3Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 Service Pack 1 (32-bit editions)
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2013 (32-bit editions)
Microsoft Office 2013 (64-bit editions)