High severity8.8NVD Advisory· Published Aug 12, 2014· Updated May 6, 2026
CVE-2014-2815
CVE-2014-2815
Description
Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability."
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- blogs.technet.com/b/srd/archive/2014/08/12/assessing-risk-for-the-august-2014-security-updates.aspxnvdPatchVendor Advisory
- docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-048nvdPatchVendor Advisory
- packetstormsecurity.com/files/164419/Microsoft-Office-OneNote-2007-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/69098nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1030717nvdThird Party AdvisoryVDB Entry
- secunia.com/advisories/60672nvdNot Applicable
News mentions
0No linked articles in our index yet.