CVE-2014-6332: Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
Other sources
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6332?
CVE-2014-6332 has a high severity rating as it allows remote code execution on affected systems.
How do I fix CVE-2014-6332?
To mitigate CVE-2014-6332, ensure that all applicable Microsoft Windows systems are updated with the latest security patches.
What systems are affected by CVE-2014-6332?
CVE-2014-6332 affects multiple Microsoft Windows versions, including Windows 7, Windows 8, Windows 8.1, and several Windows Server editions.
Can CVE-2014-6332 be exploited by attackers?
Yes, attackers can exploit CVE-2014-6332 through crafted websites to execute arbitrary code on vulnerable machines.
Is there a workaround for CVE-2014-6332 if updates cannot be applied?
A temporary workaround for CVE-2014-6332 may include disabling scripts in Internet Explorer or using alternative browsers until a patch is applied.