← Back

CVE-2014-4060

nvd nist
Published: Aug 12, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Use-after-free vulnerability in MCPlayer.dll in Microsoft Windows Media Center TV Pack for Windows Vista, Windows 7 SP1, and Windows Media Center for Windows 8 and 8.1 allows remote attackers to execute arbitrary code via a crafted Office document that triggers deletion of a CSyncBasePlayer object, aka "CSyncBasePlayer Use After Free Vulnerability."

Affected (2)

2 products
Windows Media Center
Windows Media Center Tv Pack
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Microsoft
Windows 8
All versions
Microsoft
Windows 8.1
All versions
Configuration B
1 vulnerable · 13 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows Vista
All versions

References (6)

Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.