Memory corruption in Microsoft Windows and Windows Server - CVE-2014-6332
Published: January 19, 2017 / Updated: June 17, 2021
Vulnerability identifier: #VU5112
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-6332
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to boundary error when handling malicious files. A remote attacker can create a specially crafted Microsoft office file containing the malicious OLE object, trick the victim into opening it, trigger memory corruption and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
The weakness exists due to boundary error when handling malicious files. A remote attacker can create a specially crafted Microsoft office file containing the malicious OLE object, trick the victim into opening it, trigger memory corruption and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2014-6332
Install update from vendor's website.
Links to Public Exploits and PoC-codes
- Exploit #6442 - IBM Security AppScan Standard 9.0.2 - OLE Automation Array Remote Code Execution (June 17, 2021)
- Exploit #2344 - cve-2018-8174_analysis (Analysis of VBS exploit CVE-2018-8174) (April 7, 2020)
- Exploit #831 - The World Browser 3.0 Final - Remote Code Execution (March 18, 2020)
- Exploit #832 - HTML Compiler - Remote Code Execution (March 18, 2020)
- Exploit #833 - Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064) (March 18, 2020)
- Exploit #834 - Internet Download Manager - OLE Automation Array Remote Code Execution (March 18, 2020)
- Exploit #835 - Havij - OLE Automation Array Remote Code Execution (March 18, 2020)
- Exploit #836 - Acunetix 9.5 - OLE Automation Array Remote Code Execution (March 18, 2020)
- Exploit #837 - Microsoft Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution / PowerShell VirtualAlloc (MS14-064) (March 18, 2020)
- Exploit #838 - Microsoft Internet Explorer < 11 - OLE Automation Array Remote Code Execution (Metasploit) (March 18, 2020)
- Exploit #839 - Microsoft Internet Explorer 11 - OLE Automation Array Remote Code Execution (1) (March 18, 2020)
- Exploit #1660 - MS14-064 Microsoft Internet Explorer Windows OLE Automation Array Remote Code Execution (March 18, 2020)