First published: Mon Mar 24 2014(Updated: )
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Word for Android | ||
Microsoft Office | =2011 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Web Apps | =2010-sp1 | |
Microsoft Office Web Apps | =2010-sp2 | |
Microsoft Office Web Apps Server | =2013 | |
Microsoft SharePoint Server | =2010-sp1 | |
Microsoft SharePoint Server | =2010-sp2 | |
Microsoft SharePoint Server | =2013 | |
Microsoft Word for Android | =2003-sp3 | |
Microsoft Word for Android | =2007-sp3 | |
Microsoft Word for Android | =2010-sp1 | |
Microsoft Word for Android | =2010-sp1 | |
Microsoft Word for Android | =2010-sp2 | |
Microsoft Word for Android | =2013 | |
Microsoft Word for Android | =2013 | |
Microsoft Word Viewer | ||
Microsoft Office | =2011 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Word for Android | =2010-sp1 | |
Microsoft Word for Android | =2010-sp2 | |
Microsoft Word for Android | =2013 | |
Microsoft Word for Android | =2013-sp1 | |
Microsoft Word for Android | =2013-sp1 | |
Microsoft Word Viewer | ||
=2011 | ||
=sp3 | ||
=2010-sp1 | ||
=2010-sp2 | ||
=2013 | ||
=2010-sp1 | ||
=2010-sp2 | ||
=2013 | ||
=2003-sp3 | ||
=2007-sp3 | ||
=2010-sp1 | ||
=2010-sp2 | ||
=2013 | ||
=2013 | ||
=2013-sp1 | ||
=2013-sp1 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1761 is classified as critical due to the potential for remote code execution.
To mitigate CVE-2014-1761, install the appropriate security updates from Microsoft for your affected Office products.
CVE-2014-1761 affects various versions of Microsoft Word, Office Compatibility Pack, Office for Mac, and SharePoint Server.
Yes, CVE-2014-1761 can be exploited through malicious Microsoft Word documents.
Yes, CVE-2014-1761 affects multiple versions of Office Web Apps, including Server versions.