6.8

CVE-2014-4060

Use-after-free vulnerability in MCPlayer.dll in Microsoft Windows Media Center TV Pack for Windows Vista, Windows 7 SP1, and Windows Media Center for Windows 8 and 8.1 allows remote attackers to execute arbitrary code via a crafted Office document that triggers deletion of a CSyncBasePlayer object, aka "CSyncBasePlayer Use After Free Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Media Center Version -
   Microsoft ≫ Windows 8 Version - SwEdition professional
   Microsoft ≫ Windows 8.1 Version - SwEdition professional
Microsoft ≫ Windows Media Center Tv Pack Version -
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition enterprise
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition enterprise_kn
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition enterprise_n
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition home_premium
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition home_premium_kn
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition home_premium_n
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition professional
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition professional_kn
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition professional_n
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition ultimate
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition ultimate_kn
   Microsoft ≫ Windows 7 Version - Update sp1 SwEdition ultimate_n
   Microsoft ≫ Windows Vista
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 23.5% 0.975
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

http://secunia.com/advisories/60671
Third Party Advisory
http://www.securityfocus.com/bid/69093
Third Party Advisory
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-043
Patch
Vendor Advisory