CVE-2014-1761: Microsoft Word Memory Corruption Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-02-15. EPSS: 77.5% chance of exploitation in the next 30 days.
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.
Affected products
- Microsoft Office: version 2011 only
- Microsoft Office Compatibility Pack: affected versions not specified
- Microsoft Office Web Apps: version 2010 only
- Microsoft Office Web Apps Server: version 2013 only
- Microsoft SharePoint Server: version 2010 only; version 2013 only
- Microsoft Word: version 2003 only; version 2007 only; version 2010 only; version 2013 only
- Microsoft Word Viewer: affected versions not specified
Published 2014-03-25. Last modified 2026-06-17.