Aller au contenu
Appaloosa Scout
HIGH 7.8 KEV

CVE-2014-1761

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.

CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Ajouté au KEV
2022-02-15
Deadline remédiation
2022-08-15
Action requise
Apply updates per vendor instructions.
Ransomware
Non

Apps mobiles affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
microsoft word Android cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*
microsoft word iOS cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*
microsoft word Android cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*
microsoft word iOS cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*
microsoft word Android cpe:2.3:a:microsoft:word:2010:sp1:*:*:*:*:*:*
microsoft word iOS cpe:2.3:a:microsoft:word:2010:sp1:*:*:*:*:*:*
microsoft word Android cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*
microsoft word iOS cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*
microsoft word Android cpe:2.3:a:microsoft:word:2013:*:*:*:-:*:*:*
microsoft word iOS cpe:2.3:a:microsoft:word:2013:*:*:*:-:*:*:*
microsoft word Android cpe:2.3:a:microsoft:word:2013:*:*:*:rt:*:*:*
microsoft word iOS cpe:2.3:a:microsoft:word:2013:*:*:*:rt:*:*:*
microsoft word Android cpe:2.3:a:microsoft:word:2013:sp1:*:*:-:*:*:*
microsoft word iOS cpe:2.3:a:microsoft:word:2013:sp1:*:*:-:*:*:*
microsoft word Android cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*
microsoft word iOS cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*
Voir sur NVD ↗ Catalogue CISA KEV ↗