CVE-2014-6356: Code Injection
Array index error in Microsoft Word 2007 SP3, Word 2010 SP2, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Invalid Index Remote Code Execution Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6356?
CVE-2014-6356 is rated as critical due to its potential for remote code execution.
How do I fix CVE-2014-6356?
To fix CVE-2014-6356, ensure you apply the latest security updates from Microsoft for the affected versions of Office.
What software is affected by CVE-2014-6356?
CVE-2014-6356 affects Microsoft Word 2007 SP3, Word 2010 SP2, and the Office Compatibility Pack SP3.
What kind of attacks can exploit CVE-2014-6356?
CVE-2014-6356 can be exploited by attackers to execute arbitrary code via specially crafted Office documents.
Who is at risk from CVE-2014-6356?
Users of Microsoft Word 2007, Word 2010, and the Office Compatibility Pack who have not applied the necessary updates are at risk from CVE-2014-6356.