Junglewise Threat Intelligence

CVE-2014-4077: Microsoft IME Japanese Privilege Escalation Vulnerability

CVE-2014-4077 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows Server 2003, Microsoft Office 2007, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

Microsoft Input Method Editor (IME) Japanese contains an unspecified vulnerability in IMJPDCT.EXE that allows for privilege escalation. An attacker can bypass sandbox protection mechanisms, typically by using a crafted PDF document, to elevate their privileges on the system.

Affected products

  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Office 2007 SP3
  • Microsoft Input Method Editor (IME) Japanese (IMJPDCT.EXE)

Timeline

  • 2014-11-11: disclosed: Exploited in the wild in 2014 according to Microsoft and NVD records.
  • 2014-11-11: patched: Microsoft released security bulletin MS14-078 to address the issue.
  • 2022-05-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.