CVE-2014-1759: Critical severity Microsoft Publisher vulnerability
pubconv.dll in Microsoft Publisher 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via a crafted .pub file, aka "Arbitrary Pointer Dereference Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1759?
CVE-2014-1759 has a critical severity rating because it allows remote code execution and potential denial of service.
How do I fix CVE-2014-1759?
To fix CVE-2014-1759, users should update Microsoft Publisher to the latest security patches as provided by Microsoft.
What versions of Microsoft Publisher are affected by CVE-2014-1759?
CVE-2014-1759 affects Microsoft Publisher 2003 SP3 and Microsoft Publisher 2007 SP3.
What type of attack does CVE-2014-1759 enable?
CVE-2014-1759 enables remote attackers to execute arbitrary code or cause a denial of service attack through crafted .pub files.
Is CVE-2014-1759 exploitable through phishing emails?
Yes, CVE-2014-1759 can be exploited through phishing emails that contain malicious .pub file attachments.