Junglewise Threat Intelligence

CVE-2014-6352: Microsoft Windows Code Injection Vulnerability

CVE-2014-6352 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-25

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows, Microsoft Windows 8.1, Microsoft Windows Server 2012, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

Microsoft Windows allows remote attackers to execute arbitrary code via a crafted OLE object. The vulnerability was notably exploited in the wild using malicious PowerPoint documents to bypass security features.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT Gold, 8.1

Timeline

  • 2014-10: exploited: Exploited in the wild with a crafted PowerPoint document.
  • 2022-02-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats