PT-2014-1207 · Microsoft · Office Web Apps Server+5

Ben Hawkes

+2

·

Publicado

2014-01-14

·

Atualizado

2018-10-30

·

CVE-2014-0260

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Word versions 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT Office Compatibility Pack version SP3 Word Viewer (affected versions not specified) SharePoint Server versions 2010 SP1 and SP2 and 2013 Office Web Apps versions 2010 SP1 and SP2 Office Web Apps Server version 2013
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service via a crafted Office document. This is due to errors that occur when processing specially crafted files, enabling a remote attacker to execute arbitrary code. An attacker who successfully exploits this issue could take complete control of an affected system, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Word versions 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT, update to a version that is not affected by this issue. For Office Compatibility Pack version SP3, update to a version that is not affected by this issue. For Word Viewer, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For SharePoint Server versions 2010 SP1 and SP2 and 2013, update to a version that is not affected by this issue. For Office Web Apps versions 2010 SP1 and SP2, update to a version that is not affected by this issue. For Office Web Apps Server version 2013, update to a version that is not affected by this issue.

RCE

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2014-00371
BDU:2014-00372
BDU:2014-00373
BDU:2014-00374
BDU:2014-00375
CVE-2014-0260

Produtos afetados

Office Word
Office Compatibility Pack
Office Web Apps
Office Web Apps Server
Sharepoint Server
Word Viewer