CVE-2014-1814

Description

The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that invokes the repair feature for a different application, aka Windows Installer Repair Vulnerability.

Risk Information

Base Score
7.1
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.926

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows Server 2003 (KB2918614)Windows
Security Update for Windows Vista (KB2918614)Windows
Security Update for Windows Server 2008 (KB2918614)Windows
Security Update for Windows 7 (KB2918614)Windows
Security Update for Windows 8 (KB2918614)Windows
Security Update for Windows 8.1 (KB2918614)Windows
Security Update for Windows Server 2003 x64 Edition (KB2918614)Windows
Security Update for Windows Vista for x64-based Systems (KB2918614)Windows
Security Update for Windows Server 2008 x64 Edition (KB2918614)Windows
Security Update for Windows 7 for x64-based Systems (KB2918614)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2918614)Windows
Security Update for Windows 8 for x64-based Systems (KB2918614)Windows
Security Update for Windows Server 2012 (KB2918614)Windows
Security Update for Windows 8.1 for x64-based Systems (KB2918614)Windows
Security Update for Windows Server 2012 R2 (KB2918614)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-16005Security Update for Windows Server 2003 (KB2918614)
PATCH-16006Security Update for Windows Vista (KB2918614)
PATCH-16007Security Update for Windows Server 2008 (KB2918614)
PATCH-16008Security Update for Windows 7 (KB2918614)
PATCH-16009Security Update for Windows 8 (KB2918614)
PATCH-16010Security Update for Windows 8.1 (KB2918614)
PATCH-16011Security Update for Windows Server 2003 x64 Edition (KB2918614)
PATCH-16012Security Update for Windows Vista for x64-based Systems (KB2918614)
PATCH-16013Security Update for Windows Server 2008 x64 Edition (KB2918614)
PATCH-16014Security Update for Windows 7 for x64-based Systems (KB2918614)
PATCH-16015Security Update for Windows Server 2008 R2 x64 Edition (KB2918614)
PATCH-16016Security Update for Windows 8 for x64-based Systems (KB2918614)
PATCH-16017Security Update for Windows Server 2012 (KB2918614)
PATCH-16018Security Update for Windows 8.1 for x64-based Systems (KB2918614)
PATCH-16019Security Update for Windows Server 2012 R2 (KB2918614)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234