CVE-2014-4117
Summary
| CVE | CVE-2014-4117 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-15 10:55:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 allow remote attackers to execute arbitrary code via crafted properties in a Word document, aka "Microsoft Word File Format Vulnerability." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office | 2007 | sp3 | All | All |
| Application | Microsoft | Office | 2010 | sp1 | All | All |
| Application | Microsoft | Office | 2010 | sp2 | All | All |
| Application | Microsoft | Office | 2011 | All | mac | All |
| Application | Microsoft | Office Compatibility Pack | All | sp3 | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp1 | All | All |
| Application | Microsoft | Sharepoint Server | 2010 | sp2 | All | All |
| Application | Microsoft | Word | 2010 | sp1 | All | All |
| Application | Microsoft | Word | 2010 | sp2 | All | All |
| Application | Microsoft | Word Web Apps | 2010 | gold | All | All |
| Application | Microsoft | Word Web Apps | 2010 | sp1 | All | All |
| Application | Microsoft | Word Web Apps | 2010 | sp2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA60973 - Microsoft Office Word Files Processing Arbitrary Code Execution Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Microsoft Security Bulletin MS14-061 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Microsoft Office Word File Processing CVE-2014-4117 Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.