VYPR
High severity7.8CISA KEVNVD Advisory· Published Mar 25, 2014· Updated Apr 21, 2026

CVE-2014-1761

CVE-2014-1761

Description

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.

Affected products

17
  • cpe:2.3:a:microsoft:office:2011:*:*:*:*:macos:*:*
  • cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:office_web_apps:2010:sp1:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:office_web_apps:2010:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:office_web_apps_server:2013:*:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:sharepoint_server:2010:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:sharepoint_server:2013:*:*:*:*:*:*:*
  • Microsoft/Word8 versions
    cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:word:2010:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:word:2013:*:*:*:-:*:*:*
    • cpe:2.3:a:microsoft:word:2013:*:*:*:rt:*:*:*
    • cpe:2.3:a:microsoft:word:2013:sp1:*:*:-:*:*:*
    • cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*
  • cpe:2.3:a:microsoft:word_viewer:-:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.