CVE-2014-2730

Microsoft Office 2007 SP3, 2010 SP1-SP2, 2013, and Office for Mac 2011 - Denial of Service via XML Entity Expansion

Title source: llm
STIX 2.1

Description

The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption and persistent application hang) via a crafted XML document containing a large number of nested entity references, as demonstrated by a crafted text/plain e-mail message to Outlook, a similar issue to CVE-2003-1564.

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/531722/100/0/threaded

Scores

EPSS 0.1154
EPSS Percentile 95.6%

Details

CWE
CWE-399
Status published
Products (4)
microsoft/office 2007 sp3
microsoft/office 2010 sp1 (4 CPE variants)
microsoft/office 2011
microsoft/office 2013 (2 CPE variants)
Published Apr 05, 2014
Tracked Since Feb 18, 2026