CVE-2014-1761Patch(microsoft / office)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft office systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-15. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • office
  • office_compatibility_pack
  • office_web_apps
  • office_web_apps_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
officeoffice_compatibility_packoffice_web_appsoffice_web_apps_serversharepoint_serverwordword_viewer

6 versions affected across 7 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-30: 1Active Exploitation · 2026-04-30: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-30: 104-30
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2014-1761 (CVSS 7.8) - Microsoft Word RCE via crafted RTF. Affects Word 2003-2013, Office for Mac, SharePoint. Exploited in wild March 2014. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/NLeFmUE3bV

    Post summary

    CVE‑2014‑1761 is a Microsoft Word RCE that was exploited in March 2014, and an immediate patch is recommended.

    0000031
    11 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftoffice2011macos-
Appmicrosoftoffice_compatibility_pack---
Appmicrosoftoffice_web_apps2010--
Appmicrosoftoffice_web_apps2010--
Appmicrosoftoffice_web_apps_server2013--
Appmicrosoftsharepoint_server2010--
Appmicrosoftsharepoint_server2010--
Appmicrosoftsharepoint_server2013--
Appmicrosoftword2003--
Appmicrosoftword2007--
Appmicrosoftword2010--
Appmicrosoftword2010--
Appmicrosoftword2013--
Appmicrosoftword2013--
Appmicrosoftword2013--
Appmicrosoftword2013--
Appmicrosoftword_viewer---

Explore more