Check: 2014-A-0179
Windows 2012 IAVM:
2014-A-0179
(in version v1 r30)
Title
Microsoft Input Method Editor (IME) Privilege Escalation Vulnerability (Cat I impact)
Discussion
Microsoft has released a security bulletin addressing a vulnerability in their Input Method Editor (IME) (Japanese). Input Method Editors (IMEs) help solve an issue associated with entering information in certain languages via a keyboard. To exploit this vulnerability, an attacker would access a vulnerable sandboxed application using Microsoft IME (Japanese). If successfully exploited, the attacker would escape the sandbox of a vulnerable application and gain access to the affected system with logged-in user rights.
Check Content
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-57395
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |