CVE-2013-3859

Microsoft Pinyin IME 2010 with Office 2010 SP1 - Privilege Escalation via IME Toolbar

Title source: llm
STIX 2.1

Description

Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows local users to gain privileges by starting Internet Explorer from the IME toolbar, aka "Chinese IME Vulnerability."

References (2)

Core 2
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/ncas/alerts/TA13-253A

Scores

EPSS 0.0165
EPSS Percentile 74.2%

Details

CWE
CWE-264
Status published
Products (2)
microsoft/office 2010 sp1 (3 CPE variants)
microsoft/pinyin_ime 2010 (2 CPE variants)
Published Sep 11, 2013
Tracked Since Feb 18, 2026