CVE-2014-6352 is a remote code execution vulnerability in Microsoft Windows Object Linking and Embedding (OLE). Opening a specially crafted Microsoft Office file containing malicious OLE objects can execute arbitrary code with the current user's rights. The vulnerability resulted from an insufficient fix for CVE-2014-4114 and was exploited in the wild through crafted PowerPoint documents in October 2014. Affected systems include Windows Vista SP2, Windows 7 SP1, Windows 8 and 8.1, Windows RT and RT 8.1, Windows Server 2008 SP2 and 2008 R2 SP1, and Windows Server 2012 and 2012 R2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a single Metasploit module (ms14_064_packager_run_as_admin.rb) that exploits CVE-2014-6352, a vulnerability in Microsoft Windows OLE Package Manager. The exploit targets Windows systems (Vista SP2 through Windows 8, Server 2008/2012) with Office 2010 SP2 or Office 2013 installed. The module generates a malicious PPSX (PowerPoint Show) file containing an embedded OLE object with a custom payload (Windows executable). When a victim opens the file, the payload is executed, allowing arbitrary code execution. The exploit is most reliable on Office 2010 SP2 and Office 2013. The code leverages Metasploit's file format and EXE generation capabilities, and uses a template directory to construct the PPSX file structure. The main attack vector is local (user-assisted), requiring the victim to open the crafted file. No network endpoints are involved; all fingerprintable endpoints are file paths related to the generated exploit file and its internal structure.
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2014-6352 (MS14-064), a vulnerability in Microsoft Windows OLE Package Manager, specifically targeting systems with Python for Windows installed. The exploit generates a malicious PowerPoint Show (PPSX) file containing embedded OLE objects that, when opened on a vulnerable system (preferably with Office 2010 SP2 or Office 2013), will execute arbitrary Python code. The default payload is a Python Meterpreter reverse shell, but this can be customized. The module leverages Metasploit's FILEFORMAT and EXE mixins to craft the exploit file and payload. The main attack vector is via a crafted file (PPSX) delivered to the target, and the exploit is operational and weaponized, as it is part of the Metasploit framework and supports customizable payloads. The code references several file paths within the PPSX structure (notably /ppt/embeddings/oleObject1.bin and /ppt/embeddings/oleObject2.bin) as part of the embedded payload delivery mechanism.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Microsoft Windows involving crafted OLE objects. It was exploited in the wild in October 2014 through a crafted PowerPoint document.
A previously identified OLE object linking logic bug mentioned only as historical background for comparison with CVE-2017-0199.
An Important remote code execution vulnerability in Windows OLE triggered by opening a specially crafted document containing OLE objects. Exploitation requires user interaction and permits code execution with the current user's privileges. Microsoft reported limited attacks at publication. Update KB3010788 fixes OLE memory validation; additional PowerPoint updates provide defense-in-depth protection. Documented mitigations include the OLE packager Shim Fix it, avoiding untrusted files, UAC, Protected View, least-privilege accounts, and specially configured EMET 5.0 Attack Surface Reduction.
A remote code execution vulnerability in Microsoft Windows OLE. Microsoft updated the advisory on November 11, 2014, to announce an available security update through bulletin MS14-064. The content does not describe exploitation conditions or observed attacks.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.