Microsoft Office for Mac Insecure Filesystem Permissions Vulnerability
RISK: Medium Risk
TYPE: Clients - Productivity Products
An elevation of privilege vulnerability exists in the way that folder permissions are set in certain Microsoft Office for Mac installations. An attacker could place a malicious executable in the Microsoft Office 2011 folder. If a user later logs on and runs the malicious executable, attacker-provided code can be made to execute in the security context of the current user. If the user runs the malicious executable as an administrator, the attacker could take complete control over an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The attacker would only be able to gain elevated privileges on the affected Mac computer if a user executed the malicious executable. This is not a direct elevation of privilege, but rather it is a luring attack.
Impact
- Elevation of Privilege
System / Technologies affected
- Microsoft Office for Mac 2011
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/MS12-051
Vulnerability Identifier
Source
Related Link
Share with