CVE-2014-4060

medium
Published 2014-08-12 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Use-after-free vulnerability in MCPlayer.dll in Microsoft Windows Media Center TV Pack for Windows Vista, Windows 7 SP1, and Windows Media Center for Windows 8 and 8.1 allows remote attackers to execute arbitrary code via a crafted Office document that triggers deletion of a CSyncBasePlayer object, aka "CSyncBasePlayer Use After Free Vulnerability."

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secure@microsoft.com — https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-043

OS impact

OSVersionStatusFixed in
windows windows-not-affected
windows windowsnot-affected

Application impact

VendorProductVersionsFixed
windows microsoftwindows_media_center-
windows microsoftwindows_media_center_tv_pack-

References

CWEs

CWE-416

Verify integrity in audit chain (admin only). AS-IS.