Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2013-3859

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Pinyin IME是美国微软(Microsoft)公司和中国哈尔滨工业大学共同开发的一款拼音输入法。 Microsoft Pinyin IME 2010版本中存在一个特权提升漏洞,该漏洞可能允许低特权用户提升其访问权限。

AI Predicted 6.8 Difficulty: Trivial EPSS 1.65% · P74
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2013-3859

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows local users to gain privileges by starting Internet Explorer from the IME toolbar, aka "Chinese IME Vulnerability."
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Pinyin IME 权限许可和访问控制漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Pinyin IME是美国微软(Microsoft)公司和中国哈尔滨工业大学共同开发的一款拼音输入法。 Microsoft Pinyin IME 2010版本中存在一个特权提升漏洞,该漏洞可能允许低特权用户提升其访问权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2013-3859

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-3859

登录查看更多情报信息。

Vendor Advisories for CVE-2013-3859 (2)

Same Patch Batch · n/a · 2013-09-11 · 65 CVEs total

CVE-2013-3208 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3862 Microsoft Windows 服务控制管理器双重释放漏洞
CVE-2013-3865 Microsoft Win32k 多重提取漏洞
CVE-2013-3864 Microsoft Win32k 多重提取漏洞
CVE-2013-3863 Microsoft Windows OLE 属性漏洞
CVE-2013-3849 Microsoft Word 内存损坏漏洞
CVE-2013-3848 Microsoft Word 内存损坏漏洞
CVE-2013-3847 Microsoft Word 内存损坏漏洞
CVE-2013-3845 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3209 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3850 Microsoft Word 内存损坏漏洞
CVE-2013-3207 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3206 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3205 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3204 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3203 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3202 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3201 Microsoft Internet Explorer 内存损坏漏洞
CVE-2013-3180 Microsoft SharePoint Server POST 跨站脚本漏洞
CVE-2013-3179 Microsoft SharePoint Server跨站脚本漏洞

Showing top 20 of 65 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-3859

No comments yet


Leave a comment