CVE-2011-1980: Critical severity microsoft office vulnerability
Published Sep 15, 2011
·Updated
Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka "Office Component Insecure Library Loading Vulnerability."
Affected Software
2 affected components
Microsoft Office=2007-sp2
Microsoft Office=2003-sp3
Event History
Sep 15, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1980?
CVE-2011-1980 is classified as a medium severity vulnerability.
2
How do I fix CVE-2011-1980?
To fix CVE-2011-1980, apply the latest patches provided by Microsoft for Office 2003 and Office 2007.
3
What type of vulnerability is CVE-2011-1980?
CVE-2011-1980 is an untrusted search path vulnerability that allows privilege escalation.
4
Which Microsoft Office versions are affected by CVE-2011-1980?
CVE-2011-1980 affects Microsoft Office 2003 SP3 and Office 2007 SP2.
5
What can attackers do by exploiting CVE-2011-1980?
By exploiting CVE-2011-1980, attackers can execute a Trojan horse DLL and gain local privileges.