Lucene search

K
cve[email protected]CVE-2014-4117
HistoryOct 15, 2014 - 10:55 a.m.

CVE-2014-4117

2014-10-1510:55:07
CWE-20
web.nvd.nist.gov
55
cve-2014-4117
microsoft office
word 2007
word 2010
office for mac 2011
sharepoint server 2010
word web apps 2010
remote code execution
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.7 High

AI Score

Confidence

High

0.823 High

EPSS

Percentile

98.4%

Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 allow remote attackers to execute arbitrary code via crafted properties in a Word document, aka “Microsoft Word File Format Vulnerability.”

Affected configurations

NVD
Node
microsoftofficeMatch2007sp3
OR
microsoftofficeMatch2010sp1
OR
microsoftofficeMatch2010sp2
OR
microsoftofficeMatch2011mac
OR
microsoftoffice_compatibility_packsp3
OR
microsoftsharepoint_serverMatch2010sp1
OR
microsoftsharepoint_serverMatch2010sp2
OR
microsoftwordMatch2010sp1
OR
microsoftwordMatch2010sp2
OR
microsoftword_web_appsMatch2010gold
OR
microsoftword_web_appsMatch2010sp1
OR
microsoftword_web_appsMatch2010sp2

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.7 High

AI Score

Confidence

High

0.823 High

EPSS

Percentile

98.4%