RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
BID:66639
Info
RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
| Bugtraq ID: | 66639 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Apr 03 2014 12:00AM |
| Updated: | Apr 17 2014 01:02AM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Word Viewer 0 Microsoft Word 2007 SP3 Microsoft Word 2003 SP3 Microsoft Windows XP Service Pack 3 0 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows Vista Service Pack 2 0 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft SharePoint Server 2010 SP1 Microsoft Publisher 2007 SP3 0 Microsoft Publisher 2003 SP3 Microsoft Office Web Apps 2010 SP1 Microsoft Office 2010 (64-bit edition) SP1 Microsoft Office 2010 (32-bit edition) SP1 Microsoft Office 2007 SP3 Microsoft Office 2003 SP3 Microsoft Internet Explorer 9 Microsoft Internet Explorer 8 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
Microsoft has released advance notification that on April 8, 2014, they will be releasing four security bulletins addressing multiple vulnerabilities.
The bulletins and their affected components are as follows:
Two bulletins rated 'Critical' affecting Microsoft Word and Internet Explorer.
Two bulletins rated 'Important' affecting Microsoft Windows and Microsoft Publisher.
This BID is being retired. The following individual records exist to better document the issues:
66652 Microsoft Internet Explorer CVE-2014-1755 Memory Corruption Vulnerability
66654 Microsoft Internet Explorer CVE-2014-1752 Memory Corruption Vulnerability
66648 Microsoft Internet Explorer CVE-2014-1753 Memory Corruption Vulnerability
66622 Microsoft Publisher CVE-2014-1759 Remote Code Execution Vulnerability
66653 Microsoft Internet Explorer CVE-2014-1760 Memory Corruption Vulnerability
66629 Microsoft Word File Processing CVE-2014-1758 Remote Stack Buffer Overflow Vulnerability
66614 Microsoft Word File Converting CVE-2014-1757 Remote Code Execution Vulnerability
66647 Microsoft Internet Explorer CVE-2014-1751 Memory Corruption Vulnerability
66646 Microsoft Internet Explorer CVE-2014-0235 Memory Corruption Vulnerability
66619 Microsoft Windows CVE-2014-0315 Remote Code Execution Vulnerability
66385 Microsoft Word CVE-2014-1761 Remote Memory Corruption Vulnerability
Microsoft has released advance notification that on April 8, 2014, they will be releasing four security bulletins addressing multiple vulnerabilities.
The bulletins and their affected components are as follows:
Two bulletins rated 'Critical' affecting Microsoft Word and Internet Explorer.
Two bulletins rated 'Important' affecting Microsoft Windows and Microsoft Publisher.
This BID is being retired. The following individual records exist to better document the issues:
66652 Microsoft Internet Explorer CVE-2014-1755 Memory Corruption Vulnerability
66654 Microsoft Internet Explorer CVE-2014-1752 Memory Corruption Vulnerability
66648 Microsoft Internet Explorer CVE-2014-1753 Memory Corruption Vulnerability
66622 Microsoft Publisher CVE-2014-1759 Remote Code Execution Vulnerability
66653 Microsoft Internet Explorer CVE-2014-1760 Memory Corruption Vulnerability
66629 Microsoft Word File Processing CVE-2014-1758 Remote Stack Buffer Overflow Vulnerability
66614 Microsoft Word File Converting CVE-2014-1757 Remote Code Execution Vulnerability
66647 Microsoft Internet Explorer CVE-2014-1751 Memory Corruption Vulnerability
66646 Microsoft Internet Explorer CVE-2014-0235 Memory Corruption Vulnerability
66619 Microsoft Windows CVE-2014-0315 Remote Code Execution Vulnerability
66385 Microsoft Word CVE-2014-1761 Remote Memory Corruption Vulnerability
Exploit / POC
RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
Solution:
Microsoft plans to release fixes to address these issues on April 8, 2014.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Microsoft plans to release fixes to address these issues on April 8, 2014.
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
References:
References:
- Microsoft Homepage (Microsoft)