CVE-2014-4114

HIGH KEV

MS14-060 Microsoft Windows OLE Package Manager Code Execution

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2014-4114 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 3, 2022. EIP tracks 8 public exploits from researchers including Metasploit, Mike Czumak, Vlad Ovtchinikov, including a Metasploit module exploits/windows/fileformat/ms14_064_packager_python.

AI-analyzed exploit summary This Metasploit module exploits CVE-2014-4114 (MS14-060) in Microsoft Windows OLE Package Manager to achieve remote code execution via a malicious INF file embedded in a PPSX file. It generates an INF, GIF, and PPSX file, requiring a SMB share to host the payload.

Description

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

Exploits (8)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows_x86
https://www.exploit-db.com/exploits/35020

This Metasploit module exploits CVE-2014-4114 (MS14-060) in Microsoft Windows OLE Package Manager to achieve remote code execution via a malicious INF file embedded in a PPSX file. It generates an INF, GIF, and PPSX file, requiring a SMB share to host the payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows (Vista SP2 to Windows 8, Server 2008/2012) with Office 2010/2013
No auth needed
Prerequisites: SMB/Samba share to host INF and GIF files · Target interaction to open the PPSX file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Mike Czumak · pythonremotewindows
https://www.exploit-db.com/exploits/35055

This Python script generates a malicious PowerPoint (PPSX) file exploiting CVE-2014-4114 (MS14-060) via OLE object manipulation. It embeds a remote SMB share reference to execute arbitrary code when the file is opened.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows (via PowerPoint OLE objects)
No auth needed
Prerequisites: Remote SMB share hosting payload · Victim opens malicious PPSX file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Vlad Ovtchinikov · pythonlocalwindows
https://www.exploit-db.com/exploits/35019

This Python script automates the creation of a malicious PowerPoint file (exploit.ppsx) that exploits CVE-2014-4114, a vulnerability in Microsoft Office's OLE packager. It modifies embedded OLE objects to reference a remote SMB share hosting a malicious INF and executable file, enabling remote code execution when the victim opens the file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (tested on Office 2013 Plus on Windows 7 SP1)
No auth needed
Prerequisites: Access to a remote SMB share · Malicious INF and executable files · Victim interaction to open the PowerPoint file
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
rubylocalwindows
https://www.exploit-db.com/exploits/35235

This Metasploit module exploits CVE-2014-4114 (Sandworm) via a crafted PPSX file containing malicious OLE objects, targeting Windows systems with Python installed. It leverages the OLE Package Manager vulnerability to achieve remote code execution by embedding Python payloads in the file.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows (Vista SP2 to 8, Server 2008/2012) with Python for Windows and Office 2010/2013
No auth needed
Prerequisites: Python for Windows installed · Victim opens malicious PPSX file
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
rubylocalwindows
https://www.exploit-db.com/exploits/35236

This Metasploit module exploits CVE-2014-6352 (MS14-064) by crafting a malicious PPSX file with an embedded OLE object that executes arbitrary code when opened in vulnerable Microsoft Office versions. It leverages the 'Sandworm' vulnerability to bypass patch mitigations and achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office 2010 SP2, Office 2013 on Windows 7 SP1 and other vulnerable Windows platforms
No auth needed
Prerequisites: Vulnerable Microsoft Office installation · User interaction to open the malicious PPSX file
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
pythonlocalwindows
https://www.exploit-db.com/exploits/35216

This Python script generates a malicious OLE file to exploit CVE-2014-4114, a vulnerability in Microsoft Windows OLE that allows remote code execution. The exploit embeds a payload executable into an OLE object, which can be triggered when the file is opened in vulnerable versions of Microsoft Office.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows OLE (Office 2007, 2010)
No auth needed
Prerequisites: Vulnerable version of Microsoft Office (2007, 2010) · Payload executable (<400KB) · Python 2.7
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Haifei Li, sinn3r, juan vazquez · rubypocpython
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ms14_064_packager_python.rb

This Metasploit module exploits CVE-2014-4114 by crafting a malicious PPSX file with embedded OLE objects that execute arbitrary Python code when opened, bypassing MS14-060. It leverages the 'Sandworm' vulnerability in Windows OLE Package Manager.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows OLE Package Manager (with Python for Windows installed)
No auth needed
Prerequisites: Python for Windows installed · Victim opens the malicious PPSX file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Unknown, sinn3r, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ms14_060_sandworm.rb

This Metasploit module exploits CVE-2014-4114 (Sandworm) by crafting a malicious PPSX file that leverages OLE object manipulation to execute arbitrary code via a malicious INF file hosted on a remote SMB share.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows OLE Package Manager (packager.dll) on Windows Vista SP2 to Windows 8, Server 2008/2012, with Office 2010/2013
No auth needed
Prerequisites: SMB/Samba server to host INF and payload files · Target interaction to open the PPSX file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60972
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35055
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35019
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35020
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70419
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-060
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/113140

Scores

CVSS v3 7.8
EPSS 0.9247
EPSS Percentile 99.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-03-03
VulnCheck KEV 2014-10-14
InTheWild.io 2014-10-14
ENISA EUVD EUVD-2014-4045
Status published
Products (10)
microsoft/windows_7
microsoft/windows_8
microsoft/windows_8.1
microsoft/windows_rt
microsoft/windows_rt_8.1
microsoft/windows_server_2008
microsoft/windows_server_2008 r2 sp1
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
microsoft/windows_vista
Published Oct 15, 2014
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026