First published: Tue Apr 08 2014(Updated: )
pubconv.dll in Microsoft Publisher 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via a crafted .pub file, aka "Arbitrary Pointer Dereference Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Publisher | =2003-sp3 | |
Microsoft Publisher | =2007-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1759 has a critical severity rating because it allows remote code execution and potential denial of service.
To fix CVE-2014-1759, users should update Microsoft Publisher to the latest security patches as provided by Microsoft.
CVE-2014-1759 affects Microsoft Publisher 2003 SP3 and Microsoft Publisher 2007 SP3.
CVE-2014-1759 enables remote attackers to execute arbitrary code or cause a denial of service attack through crafted .pub files.
Yes, CVE-2014-1759 can be exploited through phishing emails that contain malicious .pub file attachments.