LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2014-6352: Microsoft Windows Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 25, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2014-6352 to its Known Exploited Vulnerabilities catalog on Feb 25, 2022, with a federal patch deadline of Aug 25, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.

CVE-2014-6352 is a code injection vulnerability in Microsoft Windows that can let remote attackers run arbitrary code through a crafted OLE object. It matters because successful abuse can give an attacker control on the affected system, with potential for further lateral movement or data access if the host is not isolated. Specifics such as exact affected builds must be confirmed against the vendor advisory.

Defenders should treat this as a high-priority Windows issue in environments that process untrusted documents or OLE content, and move quickly to inventory, patch, and monitor.

How it works

This flaw falls under CWE-94 (code injection). In plain terms, the software does not adequately constrain how certain input is handled, so attacker-controlled data can be interpreted in a way that leads to execution of code the attacker chooses.

According to the CISA summary, remote attackers can execute arbitrary code via a crafted OLE object. An attacker would typically deliver or cause the system to process such an object (for example through a document or other content that embeds OLE). The precise trigger conditions, user interaction requirements, and exploitation path are not detailed here and must be confirmed against the vendor advisory. Do not assume a particular delivery method beyond what the advisory describes.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. OLE handling is common in desktop and server roles that open or render Office-related or other compound documents, as well as in any workflow that accepts untrusted files containing embedded objects.

How to remediate

Patch first. Apply the updates Microsoft provides for this issue, following the vendor instructions referenced in the CISA required action. Confirm the correct packages and reboot requirements in the official advisory before rolling out.

If you can't patch immediately

Use compensating controls until the vendor update can be applied everywhere.

If your data may have been exposed

Actively exploited vulnerabilities can lead to account takeover or broader compromise even when ransomware use is not documented for this CVE. If you suspect successful exploitation, follow your incident response process: isolate affected hosts, preserve logs, reset credentials where appropriate, and assess what data the compromised identity could reach. You can run a free exposure scan of your email addresses against known breach data to see whether related credentials or identities have appeared in prior breaches and then take follow-up steps such as password changes and MFA enforcement.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-94
Added to CISA KEVFeb 25, 2022
Federal patch deadlineAug 25, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities