SecPod

Learn Search

Search across all Learn content

← Back to Security Research
CVE-2014-1761: Zero-day vulnerability in Microsoft Word

CVE-2014-1761: Zero-day vulnerability in Microsoft Word

A zero-day vulnerability (CVE-2014-1761) in Microsoft Word is being exploited in the wild, which was discovered by the Google security team. A good vulnerability management software can prevent these attacks.

Mar 25, 2014By Veerendra GG2 min read
MS-Word-0-Day
MS-Word-0-Day

A zero-day vulnerability (CVE-2014-1761) in Microsoft Word is being exploited in the wild, which was discovered by the Google security team. A good vulnerability management software can prevent these attacks.

The vulnerability triggers while parsing malicious Rich Text Format (RTF) content that can be of use to execute arbitrary code. Vulnerability management tool can resolve these issues.

According to Microsoft Security Advisory (2953095), vulnerability is present in Microsoft Word that can be of use to execute arbitrary code. Therefore, the flaw allows attackers to take complete control of the system. 

An attack is present by convincing users to open specially crafted Rich Text Format (RTF) content using Microsoft Word or previews or through email messages in Microsoft Outlook.

According to Microsoft’s blog, the attack is in limit and very targeted in nature. The attacker included the component to bypass ASLR using Return Oriented Programming techniques and Egg Hunter techniques. However, To search and execute the main shellcode. After successful exploitation, the back door is dropping into the system. The drop backdoor is a generic malware in Visual Basic 6, which communicates over encrypted SSL traffic. To the C&C server @ IP: 185.12.44.51 Port: 443 and can install/run additional MSI components.

Affected Software list:


Microsoft is working on an official patch, and the release is in expectation for the upcoming Patch Tuesday. Meanwhile, Microsoft released a workaround, Fix an automated tool that disables the opening of Rich Text Format (RTF). Content in Microsoft Word to prevent the exploitation of this issue.

SanerNow will have the facility to fix this vulnerability soon after Microsoft presents the patch.

– Veerendra GG

Featured Posts

Open Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests
Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

CVE Research

Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

Jun 23, 2026

Open AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure
AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

CVE Research

AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

AryStinger represents a calculated shift in IoT threat methodology, abandoning noisy, destructive payloads in favor of silent, long-term reconnaissance infrastructure. By exploiting unpatched, end-of-life routers and NAS devices through decade-old vulnerabilities, the threat operator has assembled a distributed fleet of over 4,300 Executor nodes capable of conducting parallelized DNS enumeration, port scanning, and service fingerprinting at scale, all while masking origin behind residential IP addresses. With active development ongoing and a potential operational timeline stretching back to 2024, AryStinger underscores a growing and underappreciated risk: forgotten edge hardware is not merely a compliance gap but exploitable infrastructure.

Jun 23, 2026

Open From Emergence to Dominance: INC Ransomware Surpasses 830 Victims and Strengthens Its RaaS Operations
From Emergence to Dominance: INC Ransomware Surpasses 830 Victims and Strengthens Its RaaS Operations

CVE Research

From Emergence to Dominance: INC Ransomware Surpasses 830 Victims and Strengthens Its RaaS Operations

INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023. Security researchers attribute its growth to a combination of aggressive affiliate recruitment, opportunistic targeting, and the disruption of major ransomware groups such as ALPHV/BlackCat and LockBit, which created opportunities for newer actors to expand their influence within the cybercrime ecosystem.

Jun 19, 2026

Open AI Assisted CTF: Same Systems. Two Scans. Before and After Saner
AI attack surface reduction using Saner

CVE Research

AI Assisted CTF: Same Systems. Two Scans. Before and After Saner

What changed when AI tested the lab before and after Saner reduced the usable attack surface

Jun 12, 2026