Vulnerabilities > CVE-2014-2815 - Unspecified vulnerability in Microsoft Onenote 2007
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Msbulletin
bulletin_id | MS14-048 |
bulletin_url | |
date | 2014-08-12T00:00:00 |
impact | Remote Code Execution |
knowledgebase_id | 2977201 |
knowledgebase_url | |
severity | Important |
title | Vulnerability in OneNote Could Allow Remote Code Execution |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS14-048.NASL |
description | The remote host is running a version of Microsoft OneNote that is affected by a remote code execution vulnerability. By convincing a user to open a specially crafted OneNote file, a remote attacker can create an executable file in a Startup folder and thereby execute arbitrary code with current user rights. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 77166 |
published | 2014-08-12 |
reporter | This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/77166 |
title | MS14-048: Vulnerability in OneNote Could Allow Remote Code Execution (2977201) |
code |
|
References
- http://blogs.technet.com/b/srd/archive/2014/08/12/assessing-risk-for-the-august-2014-security-updates.aspx
- http://blogs.technet.com/b/srd/archive/2014/08/12/assessing-risk-for-the-august-2014-security-updates.aspx
- http://packetstormsecurity.com/files/164419/Microsoft-Office-OneNote-2007-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/164419/Microsoft-Office-OneNote-2007-Remote-Code-Execution.html
- http://secunia.com/advisories/60672
- http://secunia.com/advisories/60672
- http://www.securityfocus.com/bid/69098
- http://www.securityfocus.com/bid/69098
- http://www.securitytracker.com/id/1030717
- http://www.securitytracker.com/id/1030717
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-048
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-048