First published: Tue Aug 12 2014(Updated: )
Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft OneNote 2010 | =2007-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2815 is considered to have a high severity due to its potential for remote code execution.
To fix CVE-2014-2815, users should apply the latest security updates provided by Microsoft for OneNote 2007 SP3.
CVE-2014-2815 allows attackers to execute arbitrary code remotely by using a specially crafted OneNote file.
CVE-2014-2815 affects users of Microsoft OneNote 2007 SP3 on Windows.
An attacker exploiting CVE-2014-2815 can create an executable file in the startup folder, enabling persistent compromise.