Microsoft Office Double Delete CVE-2014-6333 Remote Code Execution Vulnerability
BID:70961
Info
Microsoft Office Double Delete CVE-2014-6333 Remote Code Execution Vulnerability
| Bugtraq ID: | 70961 |
| Class: | Unknown |
| CVE: |
CVE-2014-6333 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2014 12:00AM |
| Updated: | Nov 11 2014 12:00AM |
| Credit: | Ben Hawkes of Google Project Zero. |
| Vulnerable: |
Microsoft Word Viewer 0 Microsoft Word 2007 SP3 Microsoft Office Compatibility Pack SP3 |
| Not Vulnerable: | |
Discussion
Microsoft Office Double Delete CVE-2014-6333 Remote Code Execution Vulnerability
Microsoft Office is prone to a remote code-execution vulnerability because it fails to properly handle objects in memory.
An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
Microsoft Office is prone to a remote code-execution vulnerability because it fails to properly handle objects in memory.
An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Microsoft Office Double Delete CVE-2014-6333 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Office Double Delete CVE-2014-6333 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Word 2007 SP3
Microsoft Office Word Viewer 0
Microsoft Office Compatibility Pack SP3
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Word 2007 SP3
-
Microsoft Security Update for Microsoft Office Word 2007 (KB2899527)
http://www.microsoft.com/downloads/details.aspx?familyid=49fb5226-9469 -4cde-b9a3-d7b3af927844
Microsoft Office Word Viewer 0
-
Microsoft Security Update for Word Viewer (KB2899553)
http://www.microsoft.com/downloads/details.aspx?familyid=aca0422c-82b6 -4749-88b8-dc1d87fc5c51
Microsoft Office Compatibility Pack SP3
-
Microsoft Security Update for Microsoft Office 2007 suites (KB2899526)
http://www.microsoft.com/downloads/details.aspx?familyid=1b5b9d91-ac5e -4098-a682-12576493a2f5
References
Microsoft Office Double Delete CVE-2014-6333 Remote Code Execution Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Office Product Homepage (Microsoft)
- Microsoft Security Bulletin MS14-069 (Microsoft)