CVE-2012-1894: Medium severity microsoft office vulnerability
Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1894?
CVE-2012-1894 is classified as a medium severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2012-1894?
To fix CVE-2012-1894, ensure that the permissions for the "Applications/Microsoft Office 2011/" directory are properly restricted to avoid world-writable settings.
Who is affected by CVE-2012-1894?
Users of Microsoft Office 2011 for Mac are affected by CVE-2012-1894.
What types of attacks does CVE-2012-1894 allow?
CVE-2012-1894 allows local users to execute unauthorized code by placing Trojan horse executables in the vulnerable directories.
Is there a patch available for CVE-2012-1894?
Yes, Microsoft has released updates that address the vulnerability in CVE-2012-1894 for affected users.