CERT-In Vulnerability Note
CIVN-2014-0250
Multiple Remote Code Execution Vulnerabilities in Microsoft Word
Original Issue Date:November 12, 2014
Severity Rating: MEDIUM
Systems Affected
- Microsoft Word 2007 Service Pack 3
- Microsoft Word Viewer
- Microsoft Office Compatibility Pack Service Pack 3
Overview
Multiple remote code execution vulnerabilities have been reported in Microsoft Word which could be exploited by a remote attacker to execute arbitrary code on the targeted system in context of the logged in user.
Description
These vulnerabilities exist in Microsoft Word due to improper handling of memory objects while parsing specially crafted Word documents. A remote attacker could leverage these issues to trigger a memory corruption by enticing the user to view a specially crafted word document with an affected version of Microsoft Office software.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code on the targeted system in security context of the logged in user. If the user holds administrative privileges, the attacker could gain complete control over the targeted system.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS14-069
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/MS14-069
References
Microsoft
https://technet.microsoft.com/library/security/MS14-069
Security Tracker
http://securitytracker.com/id/1031189
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36281
http://tools.cisco.com/security/center/viewAlert.x?alertId=36282
http://tools.cisco.com/security/center/viewAlert.x?alertId=36283
CVE Name
CVE-2014-6333
CVE-2014-6334
CVE-2014-6335
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|