PT-2009-2684 · Microsoft · Office 2008 For Mac
Published
2009-09-13
·
Updated
2009-09-14
·
CVE-2008-7217
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2008 for Mac
Description
The issue concerns a security restriction bypass in Microsoft Office 2008 for Mac. When running on Macintosh systems where access to Office is restricted to administrators, the software fails to enforce this restriction for a specific user ID, 502. This allows local users with that ID to bypass the intended security policy and access Office programs. The problem is related to permissions and ownership for certain directories.
Recommendations
For Microsoft Office 2008 for Mac, consider restricting access to the affected directories to enforce the intended security policy until a fix is available. As a temporary workaround, review and adjust the permissions and ownership of the directories to prevent unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office 2008 For Mac