First published: Tue Nov 11 2014(Updated: )
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6332 has a high severity rating as it allows remote code execution on affected systems.
To mitigate CVE-2014-6332, ensure that all applicable Microsoft Windows systems are updated with the latest security patches.
CVE-2014-6332 affects multiple Microsoft Windows versions, including Windows 7, Windows 8, Windows 8.1, and several Windows Server editions.
Yes, attackers can exploit CVE-2014-6332 through crafted websites to execute arbitrary code on vulnerable machines.
A temporary workaround for CVE-2014-6332 may include disabling scripts in Internet Explorer or using alternative browsers until a patch is applied.