CVE-2014-6352
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.
- Affected products
- Office, Office Powerpoint, Windows, Windows 7, Windows 8, Windows 8.1, Windows Rt, Windows Server 2008
- Microsoft Windows 7
- All versions
- Microsoft Windows 8
- All versions
- Microsoft Windows 8.1
- All versions
- Microsoft Windows Rt
- All versions
- Microsoft Windows Rt 8.1
- All versions
- Microsoft Windows Server 2008
- All versions
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 77.6% (100th percentile)
- NVD status
- Analyzed
- Published
- 2014-10-22
CVE-2014-6352 at NVD
14 known exploits for CVE-2014-6352
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft-Office-2007-and-2010---OLE-Arbitrary-Command-Execution
MS14-064 Microsoft Windows OLE Package Manager Code Execution Exploit
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python
MS14-064 Microsoft Windows OLE Package Manager Code Execution
MS Office 2007 and 2010 - OLE Arbitrary Command Execution
MS Office 2007 and 2010 - OLE Arbitrary Command Execution Exploit
Microsoft Office 20072010 - OLE Arbitrary Command Execution
Microsoft Office 2007/2010 - OLE Arbitrary Command Execution
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
MS14-064 Microsoft Windows OLE Package Manager Code Execution
Microsoft Windows - OLE Package Manager SandWorm
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)