CVE-2010-1254: Medium severity Microsoft Open XML File Format Converter vulnerability
The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to execute arbitrary code by replacing the executable with a Trojan Horse, aka "Mac Office Open XML Permissions Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1254?
CVE-2010-1254 is considered a medium severity vulnerability due to its potential for local exploitation.
How do I fix CVE-2010-1254?
To fix CVE-2010-1254, you should apply the latest security updates provided by Microsoft for the Open XML File Format Converter.
Who is affected by CVE-2010-1254?
CVE-2010-1254 affects users of the Microsoft Open XML File Format Converter installed on Mac OS.
What type of attack does CVE-2010-1254 enable?
CVE-2010-1254 enables local users to execute arbitrary code by replacing executables with malicious files due to insecure permissions.
When was CVE-2010-1254 published?
CVE-2010-1254 was published on May 11, 2010.