CVE-2014-2778: Microsoft Office Compatibility Pack

High severity, CVSS 9.3. EPSS: 19.9% chance of exploitation in the next 30 days.

Microsoft Word 2007 SP3 and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a (1) .doc or (2) .docx document, aka "Embedded Font Vulnerability."

Affected products

Published 2014-06-11. Last modified 2026-06-17.