First published: Thu Dec 11 2014(Updated: )
Array index error in Microsoft Word 2007 SP3, Word 2010 SP2, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Invalid Index Remote Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6356 is rated as critical due to its potential for remote code execution.
To fix CVE-2014-6356, ensure you apply the latest security updates from Microsoft for the affected versions of Office.
CVE-2014-6356 affects Microsoft Word 2007 SP3, Word 2010 SP2, and the Office Compatibility Pack SP3.
CVE-2014-6356 can be exploited by attackers to execute arbitrary code via specially crafted Office documents.
Users of Microsoft Word 2007, Word 2010, and the Office Compatibility Pack who have not applied the necessary updates are at risk from CVE-2014-6356.