CVE-2014-6332
Description
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka 'Windows OLE Automation Array Remote Code Execution Vulnerability.'
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Improper Restriction of Operations within the Bounds of a Memory Buffer
StableCommon Consequences
Applicable Platforms
Microsoft Internet Explorer 11 - OLE Automation Array …
VerifiedMicrosoft Internet Explorer 11 - OLE Automation Array Remote Code Execution (1)
View Exploit Code →Microsoft Internet Explorer < 11 - OLE Automation …
Metasploit Framework (MSF)Microsoft Internet Explorer < 11 - OLE Automation Array Remote Code Execution (Metasploit)
View Exploit Code →Microsoft Internet Explorer OLE Pre-IE11 - Automation Array …
VerifiedMicrosoft Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution / PowerShell VirtualAlloc (MS14-064)
View Exploit Code →Acunetix 9.5 - OLE Automation Array Remote Code …
VerifiedAcunetix 9.5 - OLE Automation Array Remote Code Execution
View Exploit Code →Havij - OLE Automation Array Remote Code Execution
VerifiedHavij - OLE Automation Array Remote Code Execution
View Exploit Code →Internet Download Manager - OLE Automation Array Remote …
Internet Download Manager - OLE Automation Array Remote Code Execution
View Exploit Code →Microsoft Windows HTA (HTML Application) - Remote Code …
VerifiedMicrosoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064)
View Exploit Code →HTML Compiler - Remote Code Execution
VerifiedHTML Compiler - Remote Code Execution
View Exploit Code →The World Browser 3.0 Final - Remote Code …
VerifiedThe World Browser 3.0 Final - Remote Code Execution
View Exploit Code →Windows 8 by Microsoft
cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*
Windows Server 2003 by Microsoft
cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*
Windows Server 2008 by Microsoft
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
Windows Server 2012 by Microsoft
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
Windows Rt by Microsoft
cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*
Windows Server 2008 by Microsoft
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
Windows Server 2008 by Microsoft
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
Windows Vista by Microsoft
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
Windows 7 by Microsoft
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
Windows Rt 8.1 by Microsoft
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
Windows Server 2012 by Microsoft
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
Windows 8.1 by Microsoft
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*