ZeroHour

CVE-2014-1761

KEVmass

Memory Corruption RCE in Microsoft Word

CISA: Microsoft Word Memory Corruption Vulnerability

CVSS
EPSS
77%p100
Published
KEV added
AI analysis

CVE-2014-1761 is a memory corruption vulnerability (CWE-119) in Microsoft Word that can be triggered by processing a maliciously crafted document, such as one delivered as an email attachment. Successful exploitation corrupts memory in a way that allows an attacker to execute arbitrary code on the victim's system with the privileges of the current user. Anyone running an affected Microsoft Word installation is exposed, which in practice spans a very large share of business and consumer desktops given Word's ubiquity. The flaw is confirmed as exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-02-15, and EPSS assigns it a 77.5% probability of exploitation in the next 30 days (100th percentile). No public proof-of-concept is known, but the KEV listing and high EPSS indicate real-world attacker activity, and Word document flaws of this kind have historically featured in targeted APT and spear-phishing campaigns.

What to do: Apply Microsoft's security update for CVE-2014-1761 to every Word installation per vendor instructions, treating it as an actively exploited, high-priority patch. Until patched, be alert for unsolicited Word documents arriving by email, and consider file-blocking policies for documents from untrusted sources. Check that legacy Word editions within your estate are covered, since older builds that no longer receive routine updates are the most likely to remain exposed.

Affected
Microsoft Word
Estimated exposure
masshundreds of millions of Word installations worldwide (Word is the dominant word processor across enterprise desktops) — Estimated from Microsoft Word's near-ubiquity in business and government desktop fleets and its position as the default handler for common document formats, giving an affected population far above the mass threshold.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.

CISA Known Exploited Vulnerability
Affected
Microsoft Word
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Word
Weakness
CWE-119

In the news