Kingsoft Office CVE-2014-2271 Remote Code Execution Vulnerability
BID:71381
CVE-2014-2271 |Info
Kingsoft Office CVE-2014-2271 Remote Code Execution Vulnerability
| Bugtraq ID: | 71381 |
| Class: | Design Error |
| CVE: |
CVE-2014-2271 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2014 12:00AM |
| Updated: | Dec 03 2014 12:57AM |
| Credit: | Rob Miller, Nick Walker, and Jon Butler of MWR Labs. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Kingsoft Office CVE-2014-2271 Remote Code Execution Vulnerability
Kingsoft Office is prone to a vulnerability that lets attackers execute arbitrary code.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks and execute arbitrary code in the context of the affected application.
Kingsoft Office 5.3.1 is vulnerable; other versions may also be affected.
Kingsoft Office is prone to a vulnerability that lets attackers execute arbitrary code.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks and execute arbitrary code in the context of the affected application.
Kingsoft Office 5.3.1 is vulnerable; other versions may also be affected.
Exploit / POC
Kingsoft Office CVE-2014-2271 Remote Code Execution Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
Kingsoft Office CVE-2014-2271 Remote Code Execution Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
Kingsoft Office CVE-2014-2271 Remote Code Execution Vulnerability
References:
References: