CVE-2014-6332
KEVHIGH 9.3EPSS 95.0%
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 95.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-25
- Published
- 2014-11-11
- Updated
- 2025-10-22
Proof-of-concept exploits (11)
- http://packetstormsecurity.com/files/134053/Avant-Browser-Lite-Ultimate-Remote-Code-Execu…
- http://packetstormsecurity.com/files/134061/The-World-Browser-3.0-Final-Remote-Code-Execu…
- http://packetstormsecurity.com/files/134062/HTML-Compiler-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/134064/Microsoft-Compiled-HTML-Help-Remote-Code-Exec…
- http://packetstormsecurity.com/files/134079/Winamp-Bento-Browser-Remote-Code-Execution.ht…
- http://securityintelligence.com/ibm-x-force-researcher-finds-significant-vulnerability-in…
- https://forsec.nl/wp-content/uploads/2014/11/ms14_064_ie_olerce.rb_.txt
- mourr/CVE-2014-63322★ · 2016-08-29
- nao-sec/RigEK50★ · 2017-05-17
- tjjh89017/cve-2014-63322★ · 2015-01-17
- zen-tools/zenscrawler1★ · 2015-12-19
Metasploit modules (1)
ExploitDB entries (8)
- https://www.exploit-db.com/exploits/38512
- https://www.exploit-db.com/exploits/38500
- https://www.exploit-db.com/exploits/37800
- https://www.exploit-db.com/exploits/37400
- https://www.exploit-db.com/exploits/36516
- https://www.exploit-db.com/exploits/35308
- https://www.exploit-db.com/exploits/35229
- https://www.exploit-db.com/exploits/37668