Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
BID:62181
Info
Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 62181 |
| Class: | Unknown |
| CVE: |
CVE-2013-3859 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Sep 10 2013 12:00AM |
| Credit: | Wei Wang of VulnHunt |
| Vulnerable: |
Microsoft Pinyin IME 2010 (64-bit edition) 0 Microsoft Pinyin IME 2010 (32-bit edition) 0 Microsoft Office 2010 (64-bit edition) SP1 Microsoft Office 2010 (32-bit edition) SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
Microsoft Office is prone to a local privilege-escalation vulnerability that exists in the Pinyin Input Method Editor (IME).
A local attacker can exploit this issue to execute arbitrary code with system-level privileges, resulting in a complete compromise of the affected computer.
Microsoft Office is prone to a local privilege-escalation vulnerability that exists in the Pinyin Input Method Editor (IME).
A local attacker can exploit this issue to execute arbitrary code with system-level privileges, resulting in a complete compromise of the affected computer.
Exploit / POC
Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.