Sploitus

CVE-2014-4114

23 known exploits for CVE-2014-4114

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

Microsoft Windows 7
All versions
Microsoft Windows 8
All versions
Microsoft Windows 8.1
All versions
Microsoft Windows Rt
All versions
Microsoft Windows Rt 8.1
All versions
Microsoft Windows Server 2008
All versions
CVSS 2.0
9.3 HIGH
CVSS 3.1
7.8 HIGH
EPSS
81.6% (100th percentile)
NVD status
Analyzed
Published
2014-10-15
CVE-2014-4114 at NVD
Authoritative description, scoring and affected products

23 known exploits for CVE-2014-4114

Proof-of-concept code and exploit modules indexed by Sploitus

Windows-OLE-Package-Manager
2015-01-04 Vlad OvtchinikovEXPLOITPACKPython
MS14-064 Microsoft Windows OLE Package Manager Code Execution Exploit
2014-11-16 metasploitZDTRuby
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
2014-11-14 MetasploitEXPLOITDBRuby
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
2014-11-14 MetasploitEXPLOITDBRuby
MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python
2014-11-14 Haifei LiPACKETSTORMRuby
Windows OLE - Remote Code Execution "Sandworm" Exploit (MS14-060)
2014-11-13 RootSEEBUGPython
MS14-060 Microsoft Windows OLE Package Manager Code Execution
2014-11-13 RootSEEBUGRuby
Windows OLE Package Manager SandWorm Exploit
2014-11-13 RootSEEBUGPython
Microsoft Office 2007/2010 - OLE Arbitrary Command Execution
2014-11-12 Abhishek LyallEXPLOITDBPython
Microsoft Windows - OLE Remote Code Execution Sandworm (MS14-060)
2014-10-25 Mike CzumakEXPLOITPACKPython
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
2014-10-25 Mike CzumakEXPLOITDBPython
Windows OLE Package Manager CPackage::DoVerb() INF File Download Vulnerability
2014-10-24 SAINT CorporationSAINT
Windows OLE Package Manager CPackage::DoVerb() INF File Download Vulnerability
2014-10-24 SAINT CorporationSAINT
Windows OLE Package Manager CPackage::DoVerb() INF File Download Vulnerability
2014-10-24 SAINT CorporationSAINT
Windows OLE Package Manager CPackage::DoVerb() INF File Download Vulnerability
2014-10-24 SAINT CorporationSAINT
Windows OLE Package Manager SandWorm Exploit
2014-10-21 Vlad OvtchinikovZDTPython
Microsoft Windows - OLE Package Manager SandWorm
2014-10-20 Vlad OvtchinikovEXPLOITPACKPython
Microsoft Windows - OLE Package Manager SandWorm
2014-10-20 Vlad OvtchinikovEXPLOITDBPython
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
2014-10-20 MetasploitEXPLOITDBRuby
MS14-060 Microsoft Windows OLE Package Manager Code Execution Exploit
2014-10-18 metasploitZDTRuby
MS14-060 Microsoft Windows OLE Package Manager Code Execution
2014-10-18 sinn3rPACKETSTORMRuby
Immunity Canvas: SANDWORM
2014-10-15 Immunity CanvasCANVAS
MS14-060 Microsoft Windows OLE Package Manager Code Execution
2014-10-14 Unknown, sinn3r <sinn3r@metasploit.com>, juan vazquez <juan.vazquez@metasploit.com>METASPLOITRuby