6.8
CVE-2014-4060
- EPSS 23.5%
- Veröffentlicht 12.08.2014 21:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Use-after-free vulnerability in MCPlayer.dll in Microsoft Windows Media Center TV Pack for Windows Vista, Windows 7 SP1, and Windows Media Center for Windows 8 and 8.1 allows remote attackers to execute arbitrary code via a crafted Office document that triggers deletion of a CSyncBasePlayer object, aka "CSyncBasePlayer Use After Free Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Media Center Version -
Microsoft ≫ Windows 8 Version - SwEdition professional
Microsoft ≫ Windows 8.1 Version - SwEdition professional
Microsoft ≫ Windows 8.1 Version - SwEdition professional
Microsoft ≫ Windows Media Center Tv Pack Version -
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition enterprise
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition enterprise_kn
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition enterprise_n
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition home_premium
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition home_premium_kn
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition home_premium_n
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition professional
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition professional_kn
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition professional_n
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition ultimate
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition ultimate_kn
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition ultimate_n
Microsoft ≫ Windows Vista
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition enterprise_kn
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition enterprise_n
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition home_premium
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition home_premium_kn
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition home_premium_n
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition professional
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition professional_kn
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition professional_n
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition ultimate
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition ultimate_kn
Microsoft ≫ Windows 7 Version - Update sp1 SwEdition ultimate_n
Microsoft ≫ Windows Vista
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 23.5% | 0.975 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
http://secunia.com/advisories/60671
http://www.securityfocus.com/bid/69093
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-043