CVE-2014-1761: Microsoft Word Memory Corruption Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-02-15. EPSS: 77.5% chance of exploitation in the next 30 days.

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.

Affected products

  • Microsoft Office: version 2011 only
  • Microsoft Office Compatibility Pack: affected versions not specified
  • Microsoft Office Web Apps: version 2010 only
  • Microsoft Office Web Apps Server: version 2013 only
  • Microsoft SharePoint Server: version 2010 only; version 2013 only
  • Microsoft Word: version 2003 only; version 2007 only; version 2010 only; version 2013 only
  • Microsoft Word Viewer: affected versions not specified

Published 2014-03-25. Last modified 2026-06-17.