CVE-2014-2778: Buffer Overflow
Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a (1) .doc or (2) .docx document, aka "Embedded Font Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2778?
CVE-2014-2778 is rated as critical due to its potential to allow remote code execution.
How do I fix CVE-2014-2778?
To mitigate CVE-2014-2778, apply the latest security updates from Microsoft for Word 2007 SP3 and the Office Compatibility Pack SP3.
What types of files are affected by CVE-2014-2778?
CVE-2014-2778 affects .doc and .docx files that contain crafted embedded fonts.
Who is impacted by CVE-2014-2778?
Users of Microsoft Word 2007 SP3 and Microsoft Office Compatibility Pack SP3 are at risk of CVE-2014-2778.
What exploit methods are used in CVE-2014-2778?
CVE-2014-2778 can be exploited via specially crafted documents that contain malicious embedded fonts.