CVE-2014-6332 is a critical remote code execution vulnerability affecting Microsoft Windows operating systems (Windows 7, 8, 8.1, RT, Server 2003, 2008, 2012, Vista) within the OleAut32.dll component. This flaw allows attackers to execute arbitrary code by tricking a user into visiting a crafted website that exploits improper handling of array size values. With a CVSS score of 8.8 (High), it has a low attack complexity and requires user interaction, but can lead to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, with multiple public exploit modules available in Metasploit and ExploitDB, and has garnered significant community discussion and media coverage, indicating its widespread impact and continued relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.