Vulnerability Name: | CVE-2014-1756 (CCN-92027) | ||||||||
Assigned: | 2014-05-13 | ||||||||
Published: | 2014-05-13 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Untrusted search path vulnerability in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1, when the Simplified Chinese Proofing Tool is enabled, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Microsoft Office Chinese Grammar Checking Vulnerability." Per: http://cwe.mitre.org/data/definitions/426.html "CWE-426: Untrusted Search Path" | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-1756 Source: CCN Type: Microsoft Security Bulletin MS14-023 Vulnerability in Microsoft Office Could Allow Remote Code Execution (2961037) Source: CCN Type: BID-67274 Microsoft Office Chinese Grammar Checking Feature CVE-2014-1756 Remote Code Execution Vulnerability Source: MS Type: UNKNOWN MS14-023 Source: XF Type: UNKNOWN ms-office-cve20141756-code-exec(92027) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |