← Back to CVE List
Vulnerability Intelligence Report

CVE-2014-0260

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:17.83%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
microsoft office_compatibility_pack all
microsoft office_web_apps 2010
microsoft office_web_apps_server 2013
microsoft sharepoint_server 2010, 2013
microsoft word 2003, 2007, 2010, 2013
microsoft word_viewer all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
17.827%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2013-12-03T00:00:00
Published2014-01-15T02:00:00
Patch Date2014-01-14
Last Updated2024-08-06T09:13:09

LINK COPIED TO CLIPBOARD