Release date:
Updated on:
Affected Systems:
Microsoft Word 2013
Microsoft Word 2010
Microsoft Word 2007
Microsoft Word 2003
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0260
Microsoft Word is a Microsoft text processor application.
Remote Code Execution Vulnerabilities exist when the affected Microsoft Word software parses specially crafted files. Successful exploitation of these vulnerabilities can completely control the affected system.
<* Source: vendor
Link: http://technet.microsoft.com/security/bulletin/MS14-001
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
* Install the registration handler that sets moiceas A. DOC file;
* Use the officefilepaper to block the. Doc and. dot binary files;
* Do not open Office files accidentally received from untrusted sources or from trusted sources;
Vendor patch:
Microsoft
---------
Microsoft has released a Security Bulletin (MS14-001) and patches for this:
MS14-001: Vulnerabilities in Microsoft Word and Office Web Apps cocould Allow Remote Code Execution (2916605)
Link: http://technet.microsoft.com/security/bulletin/MS14-001