Lucene search

K
cve[email protected]CVE-2011-1980
HistorySep 15, 2011 - 12:26 p.m.

CVE-2011-1980

2011-09-1512:26:48
web.nvd.nist.gov
25
cve-2011-1980
microsoft office
vulnerability
local users
privileges
trojan horse dll
directory
.doc
.ppt
.xls
office component
insecure library loading
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.889 High

EPSS

Percentile

98.7%

Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka “Office Component Insecure Library Loading Vulnerability.”

Affected configurations

NVD
Node
microsoftofficeMatch2003sp3
OR
microsoftofficeMatch2007sp2

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.889 High

EPSS

Percentile

98.7%