Executive brief
Microsoft Windows allows remote attackers to execute arbitrary code via a crafted OLE object. The vulnerability was notably exploited in the wild using malicious PowerPoint documents to bypass security features.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8
- Microsoft Windows 8.1
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT Gold, 8.1
Timeline
- 2014-10: exploited: Exploited in the wild with a crafted PowerPoint document.
- 2022-02-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.