PT-2011-3548 · Microsoft · Office Input Method Editor+1

Yang Yanbei

·

Published

2011-12-14

·

Updated

2018-10-12

·

CVE-2011-2010

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office Input Method Editor (IME) for Simplified Chinese versions (affected versions not specified)
Description The issue concerns the Microsoft Office Input Method Editor (IME) for Simplified Chinese, which does not properly restrict access to configuration options. This allows local users to gain privileges via the Microsoft Pinyin IME toolbar.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2010

Affected Products

Office Input Method Editor
Pinyin Ime