LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2014-1761: Microsoft Word Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 15, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2014-1761 to its Known Exploited Vulnerabilities catalog on Feb 15, 2022, with a federal patch deadline of Aug 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.

CVE-2014-1761 is a memory corruption vulnerability in Microsoft Word that can allow remote code execution if a user opens a specially crafted document. For IT and security teams, this matters because Word is widely deployed on endpoints and often processes untrusted files from email or shared drives, giving an attacker a path to run code in the context of the signed-in user.

Public detail is limited to the CISA description and the CWE classification; confirm exact affected builds, fixed packages, and any configuration notes directly against the vendor advisory before acting.

How it works

The flaw is classed as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In products like Microsoft Word, this typically means the application mishandles certain crafted input while parsing a document structure, corrupting memory in a way that can be leveraged to alter control flow.

An attacker abuses it by delivering a malicious Word file—commonly via email attachment, download link, or file share—and tricking a user into opening it. Successful exploitation can lead to arbitrary code running with the privileges of the Word process. Specifics of the trigger format, heap or stack layout, and any required user interaction beyond opening the file are not provided in the given facts; treat the attack surface as “untrusted document opened in Word” and verify mechanics only from the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Word is typically installed as part of Microsoft Office on Windows workstations, laptops, and some terminal servers or VDI images used by knowledge workers. Inventory every endpoint and image that has Word or the Office suite present.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as described in the vendor advisory and per CISA’s required action: “Apply updates per vendor instructions.” Use your standard enterprise channel (WSUS, Microsoft Update Catalog, Intune, or Configuration Manager) to deploy the appropriate Office/Word security update to all affected systems, then verify installation via inventory.

If you can't patch immediately

Reduce risk with compensating controls until the vendor update is deployed everywhere.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities in desktop applications can lead to endpoint compromise and follow-on data theft or ransomware, although known ransomware use is not documented for this CVE. If you have indicators of exploitation, isolate affected hosts, preserve memory and disk evidence, rotate credentials accessible from those systems, and begin incident response. As a quick additional check, users can run a free exposure scan of their work email addresses against known breach datasets to see whether credentials or personal data have appeared in prior incidents unrelated to this bug.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Word
WeaknessCWE-119
Added to CISA KEVFeb 15, 2022
Federal patch deadlineAug 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities