| CVE ID | |
| CVSS SCORE | 4.3, AV:N/AC:M/Au:N/C:N/I:N/A:P |
| AFFECTED VENDORS |
Microsoft |
| AFFECTED PRODUCTS |
Office Word |
| VULNERABILITY DETAILS |
The specific flaw exists within the line formatting functionality. By providing a malformed .docx file, an attacker can cause a denial of service condition for the current user. |
| ADDITIONAL DETAILS |
08/04/2014 - Report sent to vendor -- Vendor Mitigation: The vendor did not provide any mitigations. -- Mitigation: Given the stated purpose of Microsoft Word, and the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the application to trusted files.
|
| DISCLOSURE TIMELINE |
|
| CREDIT | Alisa Esage |