Executive brief
Microsoft Input Method Editor (IME) Japanese contains an unspecified vulnerability in IMJPDCT.EXE that allows for privilege escalation. An attacker can bypass sandbox protection mechanisms, typically by using a crafted PDF document, to elevate their privileges on the system.
Affected products
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Office 2007 SP3
- Microsoft Input Method Editor (IME) Japanese (IMJPDCT.EXE)
Timeline
- 2014-11-11: disclosed: Exploited in the wild in 2014 according to Microsoft and NVD records.
- 2014-11-11: patched: Microsoft released security bulletin MS14-078 to address the issue.
- 2022-05-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.