Junglewise Threat Intelligence

CVE-2014-4114: Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability

CVE-2014-4114 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows, Microsoft Windows 8.1, Microsoft Windows Server 2012, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in Microsoft Windows Object Linking & Embedding (OLE) when handling specially crafted OLE objects within Office documents. The flaw allows attackers to execute arbitrary code if a user opens a malicious file, a technique notably used in 'Sandworm' campaign attacks.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT Gold, 8.1

Timeline

  • 2014-06: exploited: Exploitation in the wild began as part of the Sandworm attack campaign.
  • 2014-10-14: patched: Microsoft released security bulletin MS14-060 to address the vulnerability.
  • 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.

Related threats