CVE-2014-1761

Description

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
93.131

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Word 2003 (KB2878303)Windows
Security Update for Microsoft Office Word 2007 (KB2878237)Windows
Security Update for Microsoft Word 2010 (KB2863926) 32-Bit EditionWindows
Security Update for Microsoft Office 2010 (KB2863919) 32-Bit EditionWindows
Security Update for Microsoft Word 2010 (KB2863926) 64-Bit EditionWindows
Security Update for Microsoft Office 2010 (KB2863919) 64-Bit EditionWindows
Security Update for Microsoft Word 2013 (KB2863910) 32-Bit EditionWindows
Security Update for Microsoft Word 2013 (KB2863910) 64-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-15270Security Update for Microsoft Office Word 2007 (KB2878237)
PATCH-15271Security Update for Microsoft Word 2010 (KB2863926) 32-Bit Edition
PATCH-15272Security Update for Microsoft Office 2010 (KB2863919) 32-Bit Edition
PATCH-15274Security Update for Microsoft Office 2010 (KB2863919) 64-Bit Edition
PATCH-15275Security Update for Microsoft Word 2013 (KB2863910) 32-Bit Edition
PATCH-15276Security Update for Microsoft Word 2013 (KB2863910) 64-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234