CVE-2014-6335: Code Injection
Published Nov 11, 2014
·Updated
Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Invalid Pointer Remote Code Execution Vulnerability."
Affected Software
3 affected components
Microsoft Office Compatibility Pack=sp3
Microsoft Office Word Viewer
Microsoft Word=2007-sp3
Event History
Nov 11, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6335?
CVE-2014-6335 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2014-6335?
To fix CVE-2014-6335, install the latest security updates provided by Microsoft for affected products.
3
What software is affected by CVE-2014-6335?
CVE-2014-6335 affects Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3.
4
Can CVE-2014-6335 lead to data loss?
Yes, CVE-2014-6335 can lead to data loss as attackers can execute arbitrary code.
5
Is it safe to open documents with CVE-2014-6335 vulnerability?
It is not safe to open documents that may exploit CVE-2014-6335, especially from untrusted sources.