CVE-2014-1756

Microsoft Office <2013 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1, when the Simplified Chinese Proofing Tool is enabled, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Microsoft Office Chinese Grammar Checking Vulnerability."

References (1)

Core 1
Core References

Scores

EPSS 0.0860
EPSS Percentile 94.5%

Details

Status published
Products (3)
microsoft/office 2007 sp3
microsoft/office 2010 sp1 (4 CPE variants)
microsoft/office 2013 (2 CPE variants)
Published May 14, 2014
Tracked Since Feb 18, 2026