Summary
This host is missing an important security
update according to Microsoft Bulletin MS14-069.
Impact
Successful exploitation will allow remote
attackers to execute the arbitrary code, cause memory corruption and compromise the system.
Impact Level: System
Solution
Run Windows Update and update the
listed hotfixes or download and update mentioned hotfixes in the advisory from the below link,
https://technet.microsoft.com/library/security/MS14-069
Insight
The flaws are due to errors when parsing
files.
Affected
Microsoft Office Word Viewer 2007 SP3 and prior.
Detection
Get the vulnerable file version and
check appropriate patch is applied or not.
References
Severity
Classification
-
CVE CVE-2014-6333, CVE-2014-6334, CVE-2014-6335 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft .NET Framework Multiple Vulnerabilities (2916607)
- Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)
- Microsoft .NET Framework Remote Code Execution Vulnerability (2745030)
- Microsoft IIS FTP Server 'Malformed FTP List Request' DOS Vulnerability
- Microsoft .NET Framework Remote Code Execution Vulnerability (2693777)