CERT-In Vulnerability Note
CIVN-2014-0258
Microsoft Windows Input Method Editor (Japanese) Privilege Elevation Vulnerability
Original Issue Date:November 12, 2014
Severity Rating: MEDIUM
Systems Affected
- Windows Server 2003 SP2
- Windows Server 2003 x64 Edition SP2 and Itanium-based Systems sp2
- Windows Vista SP2
- Windows Vista x64 Edition SP2
- Windows Server 2008 for 32-bit Systems SP2
- Windows Server 2008 for x64-based Systems SP2 and Itanium-based Systems SP2
- Windows 7 for 32-bit Systems SP1 and x64-based Systems SP1
- Windows Server 2008 R2 for x64-based Systems SP1 and Itanium-based Systems SP1
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Microsoft Office 2007 SP3
Component Affected
- Microsoft Office 2007 IME (Japanese)
Overview
A vulnerability has been reported in Microsoft Input Method Editor (IME) for Japanese component in Microsoft Windows which could allow a remote attacker to gain elevated privileges.
Description
This vulnerability is caused due to improper handling of an associated dictionary data file by the Microsoft IME (Japanese) component of an affected system. A remote attacker could exploit this vulnerability by enticing the targeted user to open a crafted file.
Successful exploitation of this vulnerability could allow the application to run outside the sandbox which could lead to compromise the targeted system with the privileges of logged in user.
Workaround
- Use the Enhanced Mitigation Experience Toolkit (EMET)
Solution
Apply appropriate patch as mentioned in Microsoft Security Bulletin
MS14-078
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms14-078.aspx
References
Microsoft
https://technet.microsoft.com/en-us/library/security/ms14-078.aspx
Security Tracker
http://www.securitytracker.com/id/1031196
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36257
CVE Name
CVE-2014-4077
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|