Junglewise Threat Intelligence

CVE-2014-1761: Microsoft Word Memory Corruption Vulnerability

CVE-2014-1761 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-02-15

Technologies: Microsoft Word. Vendors: Microsoft.

Executive brief

Microsoft Word contains a memory corruption vulnerability when processing crafted RTF data. Successful exploitation allows remote attackers to execute arbitrary code or cause a denial of service.

Affected products

  • Microsoft Word 2003 SP3
  • Microsoft Word 2007 SP3
  • Microsoft Word 2010 SP1, SP2
  • Microsoft Word 2013 All versions, including RT
  • Microsoft Word Viewer
  • Microsoft Office Compatibility Pack SP3
  • Microsoft Office for Mac 2011
  • Microsoft Word Automation Services on SharePoint Server 2010 SP1/SP2, 2013
  • Microsoft Office Web Apps 2010 SP1/SP2, 2013

Timeline

  • 2014-03: exploited: Exploited in the wild in March 2014.
  • 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats