SB2014111103 - Vulnerability in IME (Japanese) Could Allow Elevation of Privilege



SB2014111103 - Vulnerability in IME (Japanese) Could Allow Elevation of Privilege

Published: November 11, 2014

Security Bulletin ID SB2014111103
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege escalation (CVE-ID: CVE-2014-4077)

The vulnerability allows a remote authenticated attacker to obtain elevated privileges on the target system.

The weakness exists due to improper access control in Microsoft implementation of Input Method Editor (IME) for Japanese language. A remote attacker can create a specially crafted file designed to invoke a vulnerable sandboxed application, trick the victim into opening it, gain elevated privileges and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability may result in arbitrary code execution on the vulnerable system.

Note: the vulnerability was being actively exploited.

Remediation

Install update from vendor's website.