CVE-2014-1761: Microsoft Word Memory Corruption Vulnerability
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.
Other sources
Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
— CISA
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1761?
CVE-2014-1761 is classified as critical due to the potential for remote code execution.
How do I fix CVE-2014-1761?
To mitigate CVE-2014-1761, install the appropriate security updates from Microsoft for your affected Office products.
Which Microsoft products are affected by CVE-2014-1761?
CVE-2014-1761 affects various versions of Microsoft Word, Office Compatibility Pack, Office for Mac, and SharePoint Server.
Can CVE-2014-1761 be exploited through document files?
Yes, CVE-2014-1761 can be exploited through malicious Microsoft Word documents.
Is CVE-2014-1761 related to Office Web Apps?
Yes, CVE-2014-1761 affects multiple versions of Office Web Apps, including Server versions.