CVE-2014-2778: Microsoft Office Compatibility Pack
High severity, CVSS 9.3. EPSS: 19.9% chance of exploitation in the next 30 days.
Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a (1) .doc or (2) .docx document, aka "Embedded Font Vulnerability."
Affected products
Published 2014-06-11. Last modified 2026-06-17.