CVE-2014-6352
KEVmassRemote Code Execution in Microsoft Windows via Crafted OLE Objects (CVE-2014-6352)
CISA: Microsoft Windows Code Injection Vulnerability
CVE-2014-6352 is a code injection vulnerability (CWE-94) in the way Microsoft Windows processes Object Linking and Embedding (OLE) objects, the mechanism used to embed linked or embedded content such as links, charts, or multimedia inside documents. An attacker triggers the flaw by delivering a file containing a crafted OLE object — typically an Office document such as a presentation — and persuading a user to open it; successful exploitation allows the attacker to execute arbitrary code in the context of the logged-in user, potentially giving them control of the endpoint for data theft or as a foothold for lateral movement. The vulnerability affects Microsoft Windows systems for which Microsoft shipped fixes in its November 2014 updates, so any unpatched or legacy Windows client or server remains exposed. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-25), confirming it has been used in real-world attacks, and its EPSS score of 77.6% places it in the top percentile for likely exploitation; no public proof-of-concept is recorded in the current data.
What to do: Apply Microsoft's November 2014 security updates addressing this Windows OLE vulnerability across all Windows clients and servers per vendor instructions, prioritizing legacy and internet-reachable systems. Inventory the estate for missing patches, and in the interim restrict users from opening untrusted Office documents and email attachments, since exploitation requires the file to be opened. Track the CISA KEV required action and confirm remediation evidence for this entry.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Windows
- Weakness
- CWE-94