CVE Vulnerabilities

CVE-2014-1756

Published: May 14, 2014 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Untrusted search path vulnerability in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1, when the Simplified Chinese Proofing Tool is enabled, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka Microsoft Office Chinese Grammar Checking Vulnerability.

Affected Software

Name Vendor Start Version End Version
Office Microsoft 2007-sp3 (including) 2007-sp3 (including)
Office Microsoft 2010-sp1 (including) 2010-sp1 (including)
Office Microsoft 2010-sp2 (including) 2010-sp2 (including)
Office Microsoft 2013 (including) 2013 (including)
Office Microsoft 2013-sp1 (including) 2013-sp1 (including)

References