search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Microsoft Windows Object Linking and Embedding (OLE) OleAut32 library SafeArrayRedim function vulnerable to remote code execution via Internet Explorer

Vulnerability Note VU#158647

Original Release Date: 2014-11-13 | Last Revised: 2014-11-18

Vendor Information

This advisory information is generic and does not describe any specific instance of this type of problem, so no vendors have been notified or listed here.


CVSS Metrics

Group Score Vector
Base 9.3 AV:N/AC:M/Au:N/C:C/I:C/A:C
Temporal 7.3 E:POC/RL:OF/RC:C
Environmental 7.3 CDP:ND/TD:H/CR:ND/IR:ND/AR:ND

Other Information

API URL: VINCE JSON | CSAF
Date Public: 2014-11-13
Date First Published: 2014-11-13
Date Last Updated:
Document Revision:

Sponsored by CISA.