CVE-2014-6364: Use After Free
Published Dec 11, 2014
·Updated
Use-after-free vulnerability in Microsoft Office 2007 SP3; 2010 SP2; 2013 Gold, SP1, and SP2; and 2013 RT Gold and SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
Affected Software
8 affected components
Microsoft Office=2007-sp3
Microsoft Office=2010-sp2
Microsoft Office=2010-sp2
Microsoft Office=2013
Microsoft Office=2013
Microsoft Office=2013
Microsoft Office=2013-sp1
Microsoft Office=2013-sp2
Event History
Dec 11, 2014
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6364?
CVE-2014-6364 is rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2014-6364?
To fix CVE-2014-6364, install the security updates provided by Microsoft for affected Office versions.
3
Which Microsoft Office versions are affected by CVE-2014-6364?
CVE-2014-6364 affects Microsoft Office 2007 SP3, 2010 SP2, and various versions of Office 2013.
4
What type of vulnerability is CVE-2014-6364?
CVE-2014-6364 is a use-after-free vulnerability that can be exploited through malicious Office documents.
5
Can CVE-2014-6364 be exploited remotely?
Yes, CVE-2014-6364 can be exploited remotely if a user opens a crafted Office document.