Trend Micro Security

MS11-088:Microsoft Office IME (中国語版) の脆弱性により、特権が昇格される (2652016)

  危険度: :
  CVE識別番号: CVE-2011-2010

  概要

This security update resolves a privately reported vulnerability in Microsoft Office IME (Chinese). The vulnerability could allow elevation of privilege if a logged-on user performed specific actions on a system where an affected version of the Microsoft Pinyin (MSPY) Input Method Editor (IME) for Simplified Chinese is installed. An attacker who successfully exploits this vulnerability can run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights. Only implementations of Microsoft Pinyin IME 2010 are affected by this vulnerability. Other versions of Simplified Chinese IME and other implementations of IME are not affected.

  トレンドマイクロの対策

詳しい情報については以下のサイトをご参照ください。

  影響を受けるソフトウェア

  • Microsoft Office 2010 and Microsoft Office 2010 Service Pack 1 (32-bit editions)
  • Microsoft Office 2010 and Microsoft Office 2010 Service Pack 1 (64-bit editions)
  • Microsoft Office Pinyin SimpleFast Style 2010 and Microsoft Office Pinyin New Experience Style 2010 (32-bit version) (KB2647540)
  • Microsoft Office Pinyin SimpleFast Style 2010 and Microsoft Office Pinyin New Experience Style 2010 (64-bit version) (KB2647540)