CVE-2014-4114
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."
- Affected products
- Windows, Windows 7, Windows 8, Windows 8.1, Windows Rt, Windows Server 2008, Windows Server 2012, Windows Vista
- Microsoft Windows 7
- All versions
- Microsoft Windows 8
- All versions
- Microsoft Windows 8.1
- All versions
- Microsoft Windows Rt
- All versions
- Microsoft Windows Rt 8.1
- All versions
- Microsoft Windows Server 2008
- All versions
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 81.6% (100th percentile)
- NVD status
- Analyzed
- Published
- 2014-10-15
CVE-2014-4114 at NVD
23 known exploits for CVE-2014-4114
Proof-of-concept code and exploit modules indexed by Sploitus
Windows-OLE-Package-Manager
MS14-064 Microsoft Windows OLE Package Manager Code Execution Exploit
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python
Windows OLE - Remote Code Execution "Sandworm" Exploit (MS14-060)
MS14-060 Microsoft Windows OLE Package Manager Code Execution
Windows OLE Package Manager SandWorm Exploit
Microsoft Office 2007/2010 - OLE Arbitrary Command Execution
Microsoft Windows - OLE Remote Code Execution Sandworm (MS14-060)
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
Windows OLE Package Manager CPackage::DoVerb() INF File Download Vulnerability
Windows OLE Package Manager CPackage::DoVerb() INF File Download Vulnerability
Windows OLE Package Manager CPackage::DoVerb() INF File Download Vulnerability
Windows OLE Package Manager CPackage::DoVerb() INF File Download Vulnerability
Windows OLE Package Manager SandWorm Exploit
Microsoft Windows - OLE Package Manager SandWorm
Microsoft Windows - OLE Package Manager SandWorm
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
MS14-060 Microsoft Windows OLE Package Manager Code Execution Exploit
MS14-060 Microsoft Windows OLE Package Manager Code Execution
Immunity Canvas: SANDWORM
MS14-060 Microsoft Windows OLE Package Manager Code Execution