CVE-2014-2815: Critical severity microsoft onenote 2010 vulnerability
Published Aug 12, 2014
·Updated
Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability."
Affected Software
1 affected component
Microsoft OneNote=2007-sp3
Remediation
Event History
Aug 12, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2815?
CVE-2014-2815 is considered to have a high severity due to its potential for remote code execution.
2
How do I fix CVE-2014-2815?
To fix CVE-2014-2815, users should apply the latest security updates provided by Microsoft for OneNote 2007 SP3.
3
What types of attacks are possible with CVE-2014-2815?
CVE-2014-2815 allows attackers to execute arbitrary code remotely by using a specially crafted OneNote file.
4
Who is affected by CVE-2014-2815?
CVE-2014-2815 affects users of Microsoft OneNote 2007 SP3 on Windows.
5
What can an attacker achieve with CVE-2014-2815?
An attacker exploiting CVE-2014-2815 can create an executable file in the startup folder, enabling persistent compromise.