Skip to main content

Microsoft Office for Mac Insecure Filesystem Permissions Vulnerability

Last Update Date: 11 Jul 2012 17:18 Release Date: 11 Jul 2012 4695 Views

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

An elevation of privilege vulnerability exists in the way that folder permissions are set in certain Microsoft Office for Mac installations. An attacker could place a malicious executable in the Microsoft Office 2011 folder. If a user later logs on and runs the malicious executable, attacker-provided code can be made to execute in the security context of the current user. If the user runs the malicious executable as an administrator, the attacker could take complete control over an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The attacker would only be able to gain elevated privileges on the affected Mac computer if a user executed the malicious executable. This is not a direct elevation of privilege, but rather it is a luring attack.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Microsoft Office for Mac 2011

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link