Microsoft Office CVE-2014-6362 ASLR Security Bypass Vulnerability
BID:72467
Info
Microsoft Office CVE-2014-6362 ASLR Security Bypass Vulnerability
| Bugtraq ID: | 72467 |
| Class: | Design Error |
| CVE: |
CVE-2014-6362 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2015 12:00AM |
| Updated: | Feb 10 2015 12:00AM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Office 2013 Service Pack 1 (64-bit editions) Microsoft Office 2013 Service Pack 1 (32-bit editions) Microsoft Office 2013 (64-bit editions) 0 Microsoft Office 2013 (32-bit editions) 0 Microsoft Office 2010 (64-bit edition) SP2 Microsoft Office 2010 (32-bit edition) SP2 Microsoft Office 2007 SP3 |
| Not Vulnerable: | |
Discussion
Microsoft Office CVE-2014-6362 ASLR Security Bypass Vulnerability
Microsoft Office is prone to a security-bypass vulnerability.
An attacker can leverage this issue to bypass certain security restrictions and execute arbitrary code by exploiting another vulnerability in the application.
Microsoft Office is prone to a security-bypass vulnerability.
An attacker can leverage this issue to bypass certain security restrictions and execute arbitrary code by exploiting another vulnerability in the application.
Exploit / POC
Microsoft Office CVE-2014-6362 ASLR Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Office CVE-2014-6362 ASLR Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2007 SP3
Microsoft Office 2013 (64-bit editions) 0
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2013 (32-bit editions) 0
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Office 2013 Service Pack 1 (32-bit editions)
-
Microsoft Security Update for Microsoft Office 2013 (KB2910941) 32-Bit Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=D36AB0AF-A809 -4052-BCC4-E815F5FBCC03
Microsoft Office 2007 SP3
-
Microsoft Security Update for Microsoft Office 2007 suites (KB2920795)
http://www.microsoft.com/downloads/details.aspx?FamilyId=FF4435B7-1572 -45BF-82B9-49301C590540
Microsoft Office 2013 (64-bit editions) 0
-
Microsoft Security Update for Microsoft Office 2013 (KB2910941) 64-Bit Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=BB4D5461-F196 -4F49-8B50-7A5D1B167BA9
Microsoft Office 2013 Service Pack 1 (64-bit editions)
-
Microsoft Security Update for Microsoft Office 2013 (KB2910941) 64-Bit Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=BB4D5461-F196 -4F49-8B50-7A5D1B167BA9
Microsoft Office 2013 (32-bit editions) 0
-
Microsoft Security Update for Microsoft Office 2013 (KB2910941) 32-Bit Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=D36AB0AF-A809 -4052-BCC4-E815F5FBCC03
References
Microsoft Office CVE-2014-6362 ASLR Security Bypass Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Office Product Homepage (Microsoft)
- Microsoft Security Bulletin MS15-013 (Microsoft)