Vulnerability record · CVE-2014-6352 · published 22 October 2014
CVE-2014-6352: Microsoft Windows OLE object code execution flaw
Microsoft · Windows 7
Microsoft Windows fails to properly handle crafted OLE objects, allowing remote code execution. It was exploited in the wild in October 2014 through a malicious PowerPoint document, and it affects a broad set of legacy Windows client and server releases.
Description
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a very high EPSS score, and it enables remote code execution.
What it is
Microsoft Windows fails to properly handle crafted OLE objects, allowing remote code execution. It was exploited in the wild in October 2014 through a malicious PowerPoint document, and it affects a broad set of legacy Windows client and server releases.
Impact
An attacker who gets a victim to open the crafted document can execute arbitrary code in the context of the logged-on user, giving full control of the affected system.
Attack surface
Reached locally through a crafted OLE object embedded in a document such as PowerPoint; the CVSS vector shows no privileges required but user interaction is required to open the file.
Exploitation
Listed in CISA KEV since February 2022 and exploited in the wild in October 2014; EPSS 30-day probability is 0.77553 (99.5th percentile), indicating high likelihood of attempted exploitation.
What to do
- Apply the Microsoft security update referenced in MS14-064 (KB3010060) to all affected Windows versions.
- Remove or upgrade unsupported legacy systems (Vista, Windows 7, Windows 8/8.1, RT, Server 2008/2012) that cannot receive current patches.
- Block or restrict opening of untrusted Office documents and OLE objects via email and web gateways.
- Disable or harden OLE object handling where feasible and enforce least privilege so document opening does not run with administrative rights.
Detection
- Monitor for Office or PowerPoint processes spawning unexpected child processes such as cmd.exe, powershell.exe or script hosts.
- Alert on OLE object or embedded package creation and execution events in Office documents.
- Hunt for known exploit document indicators and unusual file writes or network callbacks following document open.
- Review endpoint logs for code injection or anomalous memory activity in Office processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-6352 to the Known Exploited Vulnerabilities catalog on 25 February 2022 as "Microsoft Windows Code Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 25 August 2022.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-6352 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-6352), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.