CVE-2014-6332 (CNNVD-201411-140)
中文标题:
Windows OLE 自动化数组远程执行代码漏洞
英文标题:
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2...
漏洞描述
中文描述:
Microsoft Windows OLE(对象链接与嵌入)是美国微软(Microsoft)公司的一种允许应用程序共享数据和功能的技术。 当Internet Explorer不正确地访问内存中的对象时,存在远程执行代码漏洞。以下产品和版本受到影响:Microsoft Windows Server 2003 SP2,Windows Vista SP2,Windows Server 2008 SP2和R2 SP1,Windows 7 SP1,Windows 8,Windows 8.1,Windows Server 2012 Gold和R2,Windows RT Gold和8.1。
英文描述:
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| microsoft | windows_7 | - | - | - |
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
|
| microsoft | windows_8 | - | - | - |
cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*
|
| microsoft | windows_8.1 | - | - | - |
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
|
| microsoft | windows_rt | - | - | - |
cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*
|
| microsoft | windows_rt_8.1 | - | - | - |
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
|
| microsoft | windows_server_2003 | - | - | - |
cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*
|
| microsoft | windows_server_2008 | - | - | - |
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
|
| microsoft | windows_server_2008 | r2 | - | - |
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
|
| microsoft | windows_server_2012 | - | - | - |
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
|
| microsoft | windows_server_2012 | r2 | - | - |
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
|
| microsoft | windows_vista | - | - | - |
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
nvd.nist.gov
exploitdb
exploitdb
cve.org
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
exploitdb
CVSS评分详情
3.1 (adp)
HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2014-6332 |
2025-11-11 15:18:48 | 2025-11-11 07:33:51 |
| NVD | nvd_CVE-2014-6332 |
2025-11-11 14:54:36 | 2025-11-11 07:42:36 |
| CNNVD | cnnvd_CNNVD-201411-140 |
2025-11-11 15:09:31 | 2025-11-11 07:51:42 |
| EXPLOITDB | exploitdb_EDB-35229 |
2025-11-11 15:05:56 | 2025-11-11 08:31:02 |
| EXPLOITDB | exploitdb_EDB-35230 |
2025-11-11 15:05:56 | 2025-11-11 08:31:02 |
| EXPLOITDB | exploitdb_EDB-35308 |
2025-11-11 15:05:56 | 2025-11-11 08:31:10 |
| EXPLOITDB | exploitdb_EDB-36516 |
2025-11-11 15:05:54 | 2025-11-11 08:33:24 |
| EXPLOITDB | exploitdb_EDB-37400 |
2025-11-11 15:05:55 | 2025-11-11 08:34:45 |
| EXPLOITDB | exploitdb_EDB-37668 |
2025-11-11 15:05:56 | 2025-11-11 08:35:18 |
| EXPLOITDB | exploitdb_EDB-37800 |
2025-11-11 15:05:57 | 2025-11-11 08:35:34 |
| EXPLOITDB | exploitdb_EDB-38500 |
2025-11-11 15:05:56 | 2025-11-11 08:36:48 |
| EXPLOITDB | exploitdb_EDB-38512 |
2025-11-11 15:05:58 | 2025-11-11 08:36:49 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 34 -> 36
查看详细变更
- references_count: 32 -> 34
- tags_count: 9 -> 10
查看详细变更
- references_count: 30 -> 32
查看详细变更
- references_count: 28 -> 30
查看详细变更
- references_count: 26 -> 28
- tags_count: 8 -> 9
查看详细变更
- references_count: 24 -> 26
- tags_count: 7 -> 8
查看详细变更
- references_count: 22 -> 24
- tags_count: 5 -> 7
查看详细变更
- references_count: 20 -> 22
- tags_count: 4 -> 5
查看详细变更
- references_count: 17 -> 20
- tags_count: 0 -> 4
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 缓冲区错误
- cnnvd_id: 未提取 -> CNNVD-201411-140
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 0 -> 11
- references_count: 16 -> 17
- data_sources: ['cve'] -> ['cve', 'nvd']