CVE-2014-6360 is a critical remote code execution vulnerability affecting Microsoft Excel 2007 SP3, Excel 2010 SP2, and the Office Compatibility Pack. This flaw, dubbed "Global Free Remote Code Execution in Excel Vulnerability," allows attackers to execute arbitrary code by tricking users into opening a specially crafted Office document. With a CVSS score of 9.3, it presents a severe risk due to its network-based attack vector, medium complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or KEV listing exists, and community discussion and media coverage are minimal, the high FAUCET Risk Score of 94/100 indicates its significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:x64:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:x86:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:office_compatibility_pack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.