Vulnerabilities > CVE-2014-1756 - Remote Code Execution vulnerability in Microsoft Office 2007/2010/2013

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
microsoft
critical
nessus

Summary

Untrusted search path vulnerability in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1, when the Simplified Chinese Proofing Tool is enabled, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Microsoft Office Chinese Grammar Checking Vulnerability." Per: http://cwe.mitre.org/data/definitions/426.html "CWE-426: Untrusted Search Path"

Vulnerable Configurations

Part Description Count
Application
Microsoft
7

Msbulletin

bulletin_idMS14-023
bulletin_url
date2014-05-13T00:00:00
impactRemote Code Execution
knowledgebase_id2961037
knowledgebase_url
severityImportant
titleVulnerabilities in Microsoft Office Could Allow Remote Code Execution

Nessus

NASL familyWindows : Microsoft Bulletins
NASL idSMB_NT_MS14-023.NASL
descriptionThe remote Windows host is affected by multiple vulnerabilities : - A vulnerability exists in the way that Windows loads .dll files that could allow remote code execution if a crafted .dll file is in the same directory as an Office file being opened. When exploiting this vulnerability, an attacker could gain the same user permissions as the current user. (Proofing tools in Office 2007 SP3, Office 2010 SP1/SP2 for Simplified Chinese, Proofing tools in Office 2013 SP0/SP1) - The remote Windows host is potentially affected by a vulnerability in the way Office handles responses to opening remote network Office files. When exploiting this vulnerability, an attacker could gain the access token used to authenticate the user on a Microsoft online service. (Office 2013 SP0/SP1)
last seen2020-06-01
modified2020-06-02
plugin id73982
published2014-05-14
reporterThis script is Copyright (C) 2014-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/73982
titleMS14-023: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2961037)