Summary
This host is missing a important security
update according to Microsoft Bulletin MS14-069.
Impact
Successful exploitation will allow remote
attackers to execute the arbitrary code, cause memory corruption and compromise the system.
Impact Level: System
Solution
Run Windows Update and update the
listed hotfixes or download and update mentioned hotfixes in the advisory from the below link,
https://technet.microsoft.com/library/security/MS14-069
Insight
The flaws are due to errors when parsing
files.
Affected
Microsoft Office Word 2007 SP3 and prior.
Detection
Get the vulnerable file version and
check appropriate patch is applied or not.
References
Severity
Classification
-
CVE CVE-2014-6333, CVE-2014-6334, CVE-2014-6335 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft 'hxvz.dll' ActiveX Control Memory Corruption Vulnerability (948881)
- Microsoft .NET Framework Remote Code Execution Vulnerability (2745030)
- Microsoft DirectShow Remote Code Execution Vulnerability (961373)
- Consent User Interface Privilege Escalation Vulnerability (2442962)
- Buffer Overrun in the ListBox and in the ComboBox (824141)