CVE-2014-2262: Sas Base Sas

High severity, CVSS 9.3. EPSS: 4.3% chance of exploitation in the next 30 days.

Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a crafted SAS program.

Affected products

  • Sas Base Sas: version 9.2 only; version 9.3 only; version 9.4 only

Published 2014-03-01. Last modified 2026-06-17.