CVE-2014-4060
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
12/08/2014
Last modified:
12/04/2025
Description
Use-after-free vulnerability in MCPlayer.dll in Microsoft Windows Media Center TV Pack for Windows Vista, Windows 7 SP1, and Windows Media Center for Windows 8 and 8.1 allows remote attackers to execute arbitrary code via a crafted Office document that triggers deletion of a CSyncBasePlayer object, aka "CSyncBasePlayer Use After Free Vulnerability."
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microsoft:windows_media_center:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows_8:-:*:*:*:professional:*:*:* | ||
| cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:professional:*:*:* | ||
| cpe:2.3:a:microsoft:windows_media_center_tv_pack:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:enterprise:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:enterprise_kn:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:enterprise_n:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:home_premium:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:home_premium_kn:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:home_premium_n:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:professional:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:professional_kn:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:professional_n:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:ultimate:*:*:* | ||
| cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:ultimate_kn:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/60671
- http://www.securityfocus.com/bid/69093
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-043
- http://secunia.com/advisories/60671
- http://www.securityfocus.com/bid/69093
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-043



