Summary
This host is missing a important security
update according to Microsoft Bulletin MS14-069.
Impact
Successful exploitation will allow remote
attackers to execute the arbitrary code, cause memory corruption and compromise the system.
Impact Level: System
Solution
Run Windows Update and update the
listed hotfixes or download and update mentioned hotfixes in the advisory from the below link,
https://technet.microsoft.com/library/security/MS14-069
Insight
The flaws are due to errors when parsing
files.
Affected
Microsoft Office Word 2007 SP3 and prior.
Detection
Get the vulnerable file version and
check appropriate patch is applied or not.
References
Severity
Classification
-
CVE CVE-2014-6333, CVE-2014-6334, CVE-2014-6335 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft Active Directory Denial of Service Vulnerability (953235)
- Microsoft Internet Explorer Multiple Code Execution Vulnerabilities (974455)
- Microsoft Excel Could Allow Remote Code Execution Vulnerabilities (954066)
- Microsoft Forefront Protection For Exchange RCE Vulnerability (2927022)
- Microsoft .NET Framework Authentication Bypass and Spoofing Vulnerabilities (2836440)