Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability
Microsoft · Windows
CVSS 8.8
EPSS 95%
9 public exploits
Fix deadline passed 15 April 2022
What it is
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
Why we say that
- EPSS puts exploitation in the next 30 days at 95%
- 9 public exploits published
- CISA's federal remediation deadline (2022-04-15) has passed
- Listed in the CISA Known Exploited Vulnerabilities catalogue
Every line above comes from a named public source. Where the evidence is thin, we say so rather than inventing confidence — see methodology.
What to do
Apply updates per vendor instructions.
Public exploit code
Indexed from Exploit-DB. Presence of code raises urgency; absence does not mean safety.
- The World Browser 3.0 Final - Remote Code Execution
- HTML Compiler - Remote Code Execution
- Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064)
- Internet Download Manager - OLE Automation Array Remote Code Execution
- Havij - OLE Automation Array Remote Code Execution
- Acunetix 9.5 - OLE Automation Array Remote Code Execution
- Microsoft Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution / PowerShell VirtualAlloc (MS14-064)
- Microsoft Internet Explorer < 11 - OLE Automation Array Remote Code Execution (Metasploit)
- Microsoft Internet Explorer 11 - OLE Automation Array Remote Code Execution (1)
What it costs when this goes wrong
This is where UK enforcement meets the vulnerability record. Where an unfixed vulnerability leads to a breach, the ICO treats it as a security failure under UK GDPR. Recent cases:
- The Electoral Commission Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 20…
- Gain Capital UK Limited Gain Capital UK have been issued a Reprimand in respect of Articles 32 (2) and 32 (1) (b). An unauthorised third party leveraged a…
- Chartered Institute for Securities & Investment An unauthorised third party exploited a known vulnerability in the Sitefinity software to leverage a bruteforce attack to upload a…