CVE-2014-6356: Microsoft Office Compatibility Pack
High severity, CVSS 9.3. EPSS: 11.9% chance of exploitation in the next 30 days.
Array index error in Microsoft Word 2007 SP3, Word 2010 SP2, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Invalid Index Remote Code Execution Vulnerability."
Affected products
- Microsoft Office Compatibility Pack: any version
- Microsoft Word: version 2007 only; version 2010 only
Published 2014-12-11. Last modified 2026-06-17.