CERT-In Vulnerability Note
CIVN-2011-0181
Microsoft Office Pinyin IME local privilege escalation Vulnerability
Original Issue Date:December 14, 2011
Severity Rating: LOW
Component Affected
- Microsoft Office 2010 and Microsoft Office 2010 Service Pack 1 (32-bit editions)
- Microsoft Office 2010 and Microsoft Office 2010 Service Pack 1 (64-bit editions)
- Microsoft Office Pinyin SimpleFast/New Experience Style 2010
- Microsoft Pinyin IME 2010
Overview
A vulnerability has been reported in Microsoft Office IME (Chinese) which could be exploited by a malicious local users to gain escalated privileges.
Description
The vulnerability is due to improper security protections within the Microsoft Pinyin (MSPY) Input Method Editor (IME) as the components configuration options are available to local users. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode with elevated privileges.
Solution
Apply appropriate patches as mentioned in
MS11-088
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms11-088
References
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms11-088
Secunia
http://secunia.com/advisories/47062/
CVE Name
CVE-2011-2010
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|