RULE(RULE ID:705943)

Rule General Information
Release Date: 2018-07-23
Rule Name: Microsoft Word RTF listoverridecount Memory Corruption Vulnerability (CVE-2014-1761)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: http://technet.microsoft.com/security/advisory/2953095
MicrosoftSecurityBulletin:MS14-017
Solutions
Microsoft has released a patch MS14-017 to eliminate the vulnerability. The patch can be downloaded at:
http://technet.microsoft.com/security/bulletin/MS14-017