Security readout for executives and security teams
Plain-English summary
This is a Microsoft Office remote code execution flaw. A victim opening a crafted Office document could allow attacker-controlled code to run. The main business risk is legacy Office, Word Viewer, Compatibility Pack, SharePoint Word Automation Services, or Office Web Apps deployments that remain unpatched.
Executive priority
Treat this as a legacy-document-processing risk. If affected products still exist, remediation should be prioritized because successful exploitation could run attacker code through a common business workflow: opening or processing Office documents.
Technical view
CVE-2014-6357 is described as a use-after-free vulnerability affecting multiple Microsoft Office and related server-side document rendering components. The documented trigger is a crafted Office document, with potential arbitrary code execution. The provided bundle does not include CVSS, CWE, patched build numbers, or exploit telemetry.
Likely exposure
Exposure is most likely in legacy environments running Office 2010 SP2, Office 2013 Gold/SP1/RT, Office for Mac 2011, Word Viewer, Office Compatibility Pack SP3, SharePoint Word Automation Services, or Office Web Apps 2010/2013.
Exploitation context
The source bundle supports remote code execution via a crafted Office document. It does not provide evidence of active exploitation, and the CVE is not marked as CISA KEV in the supplied data.
Researcher notes
The supplied evidence is limited to the CVE description and Microsoft MS14-081 reference. No exploit maturity, CVSS vector, CWE, or specific fixed build data is provided. Avoid assuming active exploitation or exact patch levels without consulting the vendor bulletin.
Mitigation direction
- Review Microsoft MS14-081 guidance for affected products and required updates.
- Prioritize legacy Office and SharePoint document-processing systems.
- Restrict unnecessary exposure of Office Web Apps and SharePoint document services.
- Use email and web controls to reduce delivery of untrusted Office documents.
- Retire unsupported Office components where updates are unavailable.
Validation and detection
- Inventory installed Microsoft Office and related viewer components by version.
- Identify SharePoint Word Automation Services and Office Web Apps deployments.
- Confirm whether MS14-081 remediation is applied to affected assets.
- Review mail and web filtering coverage for Office document delivery.
- Check vulnerability management records for CVE-2014-6357 status.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2014-6357 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- MS14-081CVE reference · vendor-advisory, x_refsource_MS
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
