CERT-In Vulnerability Note
CIVN-2014-0277
Remote Code Execution Vulnerability in Microsoft Office
Original Issue Date:December 10, 2014
Severity Rating: HIGH
Systems Affected
- Microsoft Office 2007 SP3
- Microsoft Office 2010 SP2 (32-bit editions)
- Microsoft Office 2010 SP2 (64-bit editions)
- Microsoft Office 2013 (32-bit editions)
- Microsoft Office 2013 (64-bit editions)
- Microsoft Office 2013 SP1 (32- bit editions)
- Microsoft Office 2013 SP1 (64-bit editions)
- Microsoft Office 2013 RT
- Microsoft Office 2013 RT SP1
Overview
A remote code execution vulnerability has been reported in Microsoft office which could be exploited by an unauthenticated remote attacker to execute arbitrary code in the target system.
Description
This vulnerability exists in Microsoft office due to the improper handling of memory objects while parsing crafted Office files. A remote attacker could exploit this vulnerability by enticing a user to view a specially crafted office file to trigger a memory corruption in context of the affected software.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the targeted system in security context of the logged in user. If the user holds administrative privileges, the attacker could gain complete control of the affected system which allow him to, install programs, view, change, or delete data or create new accounts in security context of the logged in user.
Solution
Apply appropriate updates as mentioned in
MS14-082
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/MS14-082
References
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36607
Microsoft
https://technet.microsoft.com/en-us/library/security/MS14-082
Security Focus
http://www.securityfocus.com/bid/71474
Symantec
http://www.symantec.com/security_response/vulnerability.jsp?bid=71474&om_rssid=sr-advisories
Security Tracker
http://www.securitytracker.com/id/1031319
Secunia
http://secunia.com/advisories/61150/
CVE Name
CVE-2014-6364
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|