RULE(RULE ID:710410)

Rule General Information
Release Date: 2016-07-20
Rule Name: FILE-OFFICE Microsoft Office Word and Web Apps Memory Corruption Vulnerability -3 (CVE-2014-4117)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 allow remote attackers to execute arbitrary code via crafted properties in a Word document, aka "Microsoft Word File Format Vulnerability."
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS14-061
SecurityFocusBID:70360
Solutions
Microsoft has released a patch MS14-061 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS14-061