7.2

CVE-2011-2010

The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local users to gain privileges via the Microsoft Pinyin (aka MSPY) IME toolbar, aka "Pinyin IME Elevation Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Pinyin Ime Version 2010 Edition x64
Microsoft ≫ Pinyin Ime Version 2010 Edition x86
Microsoft ≫ Pinyin New Experience Style Version 2010 Edition x64
Microsoft ≫ Pinyin New Experience Style Version 2010 Edition x86
Microsoft ≫ Pinyin Simple Fast Style Version 2010 Edition x64
Microsoft ≫ Pinyin Simple Fast Style Version 2010 Edition x86
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.7% 0.749
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.us-cert.gov/cas/techalerts/TA11-347A.html
US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-088