CVE-2014-1759: Microsoft Publisher

High severity, CVSS 9.3. EPSS: 14.3% chance of exploitation in the next 30 days.

pubconv.dll in Microsoft Publisher 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via a crafted .pub file, aka "Arbitrary Pointer Dereference Vulnerability."

Affected products

  • Microsoft Publisher: version 2003 only; version 2007 only

Published 2014-04-08. Last modified 2026-06-17.