A remote code execution vulnerability in Microsoft Windows Object Linking and Embedding (OLE) affects Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows RT. The flaw can be triggered when a user opens a specially crafted document containing a malicious OLE object, including PowerPoint documents observed in in-the-wild exploitation. The issue was described as an insufficient fix for CVE-2014-4114, allowing attackers to bypass the earlier patch and achieve arbitrary code execution through crafted OLE content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a single Metasploit module (ms14_064_packager_run_as_admin.rb) that exploits CVE-2014-6352, a vulnerability in Microsoft Windows OLE Package Manager. The exploit targets Windows systems (Vista SP2 through Windows 8, Server 2008/2012) with Office 2010 SP2 or Office 2013 installed. The module generates a malicious PPSX (PowerPoint Show) file containing an embedded OLE object with a custom payload (Windows executable). When a victim opens the file, the payload is executed, allowing arbitrary code execution. The exploit is most reliable on Office 2010 SP2 and Office 2013. The code leverages Metasploit's file format and EXE generation capabilities, and uses a template directory to construct the PPSX file structure. The main attack vector is local (user-assisted), requiring the victim to open the crafted file. No network endpoints are involved; all fingerprintable endpoints are file paths related to the generated exploit file and its internal structure.
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2014-6352 (MS14-064), a vulnerability in Microsoft Windows OLE Package Manager, specifically targeting systems with Python for Windows installed. The exploit generates a malicious PowerPoint Show (PPSX) file containing embedded OLE objects that, when opened on a vulnerable system (preferably with Office 2010 SP2 or Office 2013), will execute arbitrary Python code. The default payload is a Python Meterpreter reverse shell, but this can be customized. The module leverages Metasploit's FILEFORMAT and EXE mixins to craft the exploit file and payload. The main attack vector is via a crafted file (PPSX) delivered to the target, and the exploit is operational and weaponized, as it is part of the Metasploit framework and supports customizable payloads. The code references several file paths within the PPSX structure (notably /ppt/embeddings/oleObject1.bin and /ppt/embeddings/oleObject2.bin) as part of the embedded payload delivery mechanism.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously identified OLE object linking logic bug mentioned only as historical background for comparison with CVE-2017-0199.
A Microsoft vulnerability explicitly listed as exploited by the PLEAD campaign for infection.
A Microsoft Office/PowerPoint vulnerability leveraged via malicious PowerPoint files to execute attacker-controlled code as part of spear-phishing and watering-hole delivery chains.
A Windows OLE remote code execution vulnerability addressed by MS14-064; significant because it was exploited in the wild as a zero-day and resulted from an insufficient fix for CVE-2014-4114.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.