Summary
This host is missing a important security
update according to Microsoft Bulletin MS14-069.
Impact
Successful exploitation will allow remote
attackers to execute the arbitrary code, cause memory corruption and compromise the system.
Impact Level: System
Solution
Run Windows Update and update the
listed hotfixes or download and update mentioned hotfixes in the advisory from the below link,
https://technet.microsoft.com/library/security/MS14-069
Insight
The flaws are due to errors when parsing
files.
Affected
Microsoft Office Word 2007 SP3 and prior.
Detection
Get the vulnerable file version and
check appropriate patch is applied or not.
References
Severity
Classification
-
CVE CVE-2014-6333, CVE-2014-6334, CVE-2014-6335 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Cumulative Patch for Internet Information Services (Q327696)
- Cumulative Security Update for Internet Explorer (928090)
- Microsoft Foundation Classes Could Allow Remote Code Execution Vulnerability (2387149)
- ISA Server 2000 and Proxy Server 2.0 Internet Content Spoofing (888258)
- Message Queuing Remote Code Execution Vulnerability (951071) - Remote