CyberSec.Space Logo
返回 CVE 浏览器

CVE-2014-6332

Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score67.6220%
EPSS Percentile95.05th
Published2014年11月11日
Last Modified2026年4月22日

Vulnerability Description

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."

Affected Platforms (CPE)

💻
Microsoft

Windows 7

All versions
💻
Microsoft

Windows 8

All versions
💻
Microsoft

Windows 8.1

All versions
💻
Microsoft

Windows Rt

All versions
💻
Microsoft

Windows Rt 8.1

All versions
💻
Microsoft

Windows Server 2003

All versions
💻
Microsoft

Windows Server 2008

All versions
💻
Microsoft

Windows Server 2008

= r2
💻
Microsoft

Windows Server 2008

= r2
💻
Microsoft

Windows Server 2012

All versions
💻
Microsoft

Windows Server 2012

= r2
💻
Microsoft

Windows Vista

All versions

References & Advisories

相关漏洞威胁