CVE-2014-6352

microsoft windows 7, microsoft windows 8, microsoft windows 8.1

Published 22 Oct 2014 · updated 17 Jun 2026 · Analyzed

7.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 25 Feb 2022, with a remediation deadline of 25 Aug 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.

References