Lucene search

K
nvd[email protected]NVD:CVE-2011-0107
HistoryApr 13, 2011 - 6:55 p.m.

CVE-2011-0107

2011-04-1318:55:01
web.nvd.nist.gov
5

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0.167

Percentile

96.1%

Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka β€œOffice Component Insecure Library Loading Vulnerability.”

Affected configurations

Nvd
Node
microsoftofficeMatch2003sp3
OR
microsoftofficeMatch2007sp2
OR
microsoftofficeMatchxpsp3
VendorProductVersionCPE
microsoftoffice2003cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
microsoftoffice2007cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:*
microsoftofficexpcpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0.167

Percentile

96.1%