High severity7.8CISA KEVNVD Advisory· Published Mar 25, 2014· Updated Apr 21, 2026
CVE-2014-1761
CVE-2014-1761
Description
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.
Affected products
17- cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_web_apps:2010:sp1:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:office_web_apps:2010:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office_web_apps_server:2013:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2013:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:word:2010:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:word:2013:*:*:*:-:*:*:*
- cpe:2.3:a:microsoft:word:2013:*:*:*:rt:*:*:*
- cpe:2.3:a:microsoft:word:2013:sp1:*:*:-:*:*:*
- cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*
- cpe:2.3:a:microsoft:word_viewer:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- technet.microsoft.com/security/advisory/2953095nvdPatchVendor Advisory
- docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-017nvdPatchVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.