← Vulnerability feed

Vulnerability record · CVE-2014-6352 · published 22 October 2014

CVE-2014-6352: Microsoft Windows OLE object code execution flaw

Microsoft · Windows 7

Microsoft Windows fails to properly handle crafted OLE objects, allowing remote code execution. It was exploited in the wild in October 2014 through a malicious PowerPoint document, and it affects a broad set of legacy Windows client and server releases.

7.8 CVSS 3.1 High CISA KEV since 25 Feb 2022 EPSS 77% · top 0.5%
7.8CVSS 3.1 base score, v2 9.3
77%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
8Affected product versions listed by NVD
17References
17 Jun 2026Last modified by NVD

Description

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a very high EPSS score, and it enables remote code execution.

What it is

Microsoft Windows fails to properly handle crafted OLE objects, allowing remote code execution. It was exploited in the wild in October 2014 through a malicious PowerPoint document, and it affects a broad set of legacy Windows client and server releases.

Impact

An attacker who gets a victim to open the crafted document can execute arbitrary code in the context of the logged-on user, giving full control of the affected system.

Attack surface

Reached locally through a crafted OLE object embedded in a document such as PowerPoint; the CVSS vector shows no privileges required but user interaction is required to open the file.

Exploitation

Listed in CISA KEV since February 2022 and exploited in the wild in October 2014; EPSS 30-day probability is 0.77553 (99.5th percentile), indicating high likelihood of attempted exploitation.

What to do

  • Apply the Microsoft security update referenced in MS14-064 (KB3010060) to all affected Windows versions.
  • Remove or upgrade unsupported legacy systems (Vista, Windows 7, Windows 8/8.1, RT, Server 2008/2012) that cannot receive current patches.
  • Block or restrict opening of untrusted Office documents and OLE objects via email and web gateways.
  • Disable or harden OLE object handling where feasible and enforce least privilege so document opening does not run with administrative rights.

Detection

  • Monitor for Office or PowerPoint processes spawning unexpected child processes such as cmd.exe, powershell.exe or script hosts.
  • Alert on OLE object or embedded package creation and execution events in Office documents.
  • Hunt for known exploit document indicators and unusual file writes or network callbacks following document open.
  • Review endpoint logs for code injection or anomalous memory activity in Office processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-6352 to the Known Exploited Vulnerabilities catalog on 25 February 2022 as "Microsoft Windows Code Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 25 August 2022.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-risk-for-the-november-2014-security-updates.aspx Broken LinkPatchVendor Advisory
http://secunia.com/advisories/61803 Broken Link
http://twitter.com/ohjeongwook/statuses/524795124270653440 Third Party Advisory
http://www.securityfocus.com/bid/70690 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1031097 Broken LinkThird Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-064 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/97714 Third Party AdvisoryVDB Entry
https://technet.microsoft.com/library/security/3010060 PatchVendor Advisory
http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-risk-for-the-november-2014-security-updates.aspx Broken LinkPatchVendor Advisory
http://secunia.com/advisories/61803 Broken Link
http://twitter.com/ohjeongwook/statuses/524795124270653440 Third Party Advisory
http://www.securityfocus.com/bid/70690 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1031097 Broken LinkThird Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-064 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/97714 Third Party AdvisoryVDB Entry
https://technet.microsoft.com/library/security/3010060 PatchVendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-6352 US Government Resource

Track CVE-2014-6352 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed8.8CVE-2023-21674Windows ALPC use-after-free privilege escalationCVE-2023-21674 is a use-after-free (CWE-416) in the Windows Advanced Local Procedure Call (ALPC) subsystem that allows elevation of privilege. It aff…KEVEPSS 41%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2022-26923Microsoft Active Directory Domain Services certificate validation privilege escalationActive Directory Domain Services fails to properly validate certificate attributes, allowing a low-privileged domain user to obtain a certificate tha…KEVEPSS 84%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2021-34527Windows Print Spooler privileged file operation RCE (PrintNightmare)The Windows Print Spooler service improperly performs privileged file operations, allowing an attacker to execute arbitrary code as SYSTEM. This is t…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2014-6352), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.