Junglewise Threat Intelligence

CVE-2014-6332: Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability

CVE-2014-6332 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-03-25

Technologies: Microsoft Windows, Microsoft Windows 8.1. Vendors: Microsoft.

Executive brief

OleAut32.dll in Microsoft Windows OLE fails to properly handle size values during array redimensioning in the SafeArrayDimen function. This allows remote attackers to execute arbitrary code when a user visits a specially crafted website.

Affected products

  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2 and R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012 Gold and R2
  • Microsoft Windows RT Gold and 8.1

Timeline

  • 2014-11-11: advisory: Microsoft Security Bulletin MS14-064 published
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: disclosed: NVD publication date

Related threats