Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-6352

96
FAUCET Score

CVE-2014-6352 is a critical remote code execution vulnerability affecting multiple versions of Microsoft Windows and Windows Server, including Vista, 7, 8, 8.1, Server 2008, and Server 2012. This flaw allows attackers to execute arbitrary code by tricking users into opening a crafted OLE object, such as a malicious PowerPoint document. With a CVSS score of 7.8 (HIGH) and a FAUCET Risk Score of 100/100, the vulnerability presents a significant risk due to its high impact on confidentiality, integrity, and availability. The attack vector is local, requiring user interaction (UI:R), but the exploit complexity is low (AC:L). This vulnerability has been actively exploited in the wild since October 2014, notably in campaigns like "Sandworm." Exploit code is publicly available, including multiple Metasploit modules and entries on ExploitDB, confirming its ease of exploitation. The high EPSS score (0.90729) and extensive community discussion (98th percentile) further underscore its widespread recognition and active threat status.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
77.55%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Feb 25, 2022
Metasploit: MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python · Nov 12, 2014
ExploitDB: EDB-35236 · Nov 14, 2014
This CVE's current EPSS score of 0.7755 is in the 100th percentile among its peer group of 11,615 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
blogs.technet.com / b/srd/archive/2014/11/11/assessing-risk-for-the-november-2014-security-updates.aspx
Broken LinkPatchVendor Advisory
docs.microsoft.com / en-us/security-updates/securitybulletins/2014/ms14-064
PatchVendor Advisory
secunia.com / advisories/61803
Broken Link
exchange.xforce.ibmcloud.com / vulnerabilities/97714
Third Party AdvisoryVDB Entry
technet.microsoft.com / library/security/3010060
PatchVendor Advisory
twitter.com / ohjeongwook/statuses/524795124270653440
Third Party Advisory
securityfocus.com / bid/70690
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1031097
Broken LinkThird Party AdvisoryVDB Entry