First published: Tue Jul 10 2012(Updated: )
Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2011 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1894 is classified as a medium severity vulnerability due to the potential for privilege escalation.
To fix CVE-2012-1894, ensure that the permissions for the "Applications/Microsoft Office 2011/" directory are properly restricted to avoid world-writable settings.
Users of Microsoft Office 2011 for Mac are affected by CVE-2012-1894.
CVE-2012-1894 allows local users to execute unauthorized code by placing Trojan horse executables in the vulnerable directories.
Yes, Microsoft has released updates that address the vulnerability in CVE-2012-1894 for affected users.